Uber Said to Ignore Bug in Its Two-Factor Authentication

Advertisement
By Indo-Asian News Service | Updated: 22 January 2018 17:12 IST

Ride-hailing app Uber has reportedly ignored a security flaw -- discovered by a New Delhi-based security researcher -- that can allow an attacker to hack into user accounts via bypassing its two-factor authentication feature.

"Two-factor authentication is a vital part of protecting online accounts that adds a second layer of security on top of your username and password -- which can be stolen -- by sending a code by text message to your phone which only you would have access to," tech website ZDNet reported late on Sunday.

"That two-factor code can be bypassed, making the second layer of security protection effectively useless," security researcher Karan Saini was quoted as saying by ZDNet.

Advertisement

The security bug works by exploiting a weakness in how the app authenticates a user when they log in to the platform, thereby letting the user log in to an account and easily defeat the two-factor prompt, without entering the correct code.

Advertisement

Uber reportedly said the security bug "is not a particularly severe" issue.

"This isn't a particularly severe report and is likely expected behaviour," Rob Fletcher, Security Engineering Manager at Uber, said in his correspondence with Saini about the bug report.

Advertisement

Uber began testing two-factor authentication on its systems in 2015 but the company has yet to widely push the security feature to its users.

 

Catch the latest from the Consumer Electronics Show on Gadgets 360, at our CES 2026 hub.

Further reading: Uber, Apps, India
Advertisement

Related Stories

Popular Mobile Brands
  1. These OnePlus, Samsung Phones Will Be on Sale During Amazon's Next Sale
  2. Vivo Y500i With a 7,200mAh Battery, 50-Megapixel Camera Launched
  3. Amazon Great Republic Day Sale 2026: iQOO Smartphone Deals Revealed
  4. Grok Banned in Indonesia and Malaysia Following Deepfake Image Concerns
  5. Apple AirPods Pro 3 Review: The New Gold Standard
  6. Disney+ to Launch Vertical Video Feed to Rival TikTok, YouTube Shorts
  7. Google's New UCP Protocol Will Enable Direct Purchases Within Google Search
  8. Google Adds AI-Powered 'Business Agent' Feature to Search for Shoppers
  9. Govt Denies Seeking Source Code from Smartphone Makers Amid Calls for Pushback
  1. Instagram Denies Reports of Hacking and Data Breach, Says ‘Accounts Are Secure’
  2. Shell OTT Release Date: When and Where to Watch Elizabeth Moss and Kate Hudson’s Psychological Drama Online?
  3. Nikita Roy Now Available for Streaming on JioHotstar: Know Everything About Sonakshi Sinha’s Mystery Horror Film
  4. Amazon Great Republic Day Sale 2026: Acer, Dell, and Asus Laptops to Get Up to 45 Percent Discount
  5. Redmi Turbo 5 Pro Max Likely to Launch With MediaTek Dimensity 9500s Chipset, 16GB of RAM: Report
  6. Grok Banned in Indonesia and Malaysia Following Deepfake Image Concerns
  7. Amazon Great Republic Day Sale 2026: Discounts on OnePlus 15, Samsung Galaxy A55 and More Smartphones Revealed
  8. Govt Calls Demand for Smartphone OS Source Code Fake, Says Consulting Stakeholders
  9. Disney+ to Launch Vertical Video Feed to Rival TikTok, YouTube Shorts
  10. Google Brings Business Agent AI Shopping Tool to Search Alongside New Checkout, Ad Features
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.