AT&T is taking some well-deserved heat for a Web security flaw resulting in the exposure of more than 114,000 iPad 3G owners’ e-mail addresses. Apple–by proxy–has also drawn some criticism as it apparently has some culpability in defining the authentication mechanism that was exploited. It is obviously a huge embarrassment for both AT&T and Apple, but the underlying issues, and other Web security issues like it, are actually quite common.
In truth, there was nothing elite (or ‘l33t’ in hacker speak) about the iPad 3G data leak. In fact, according to an interview on CBS News by Larry Magid with Goatse Security analyst Jim Jeffers, the security researchers more or less stumbled upon the authentication glitch.