You have absolutely no idea how simple or difficult it would be for BT to fix the problem unless you are an expert working for the BT mail team.
Agree the requests should be locked out after, say, 5 attempts.
But thinking about this a bit more, the hacker must use a consistent number and expect it to be accurate once in 10,000 attempts if all the numbers are used. However, if only a subset of numbers is used it becomes much more difficult. If the hacker chooses a number that isn't generated they will never crack it. If the hacker changes the number they are using, it means 2 sets of numbers are chasing each other and increases the odds immensely. Or am I missing something?
Its just probably, each attempt has a 1/10,000 chance of being right. If they target say 1000 email addresses and each barrage is around 100 texts per account (this is what I was getting) that's 100,000 attempts. On average that will get 10 accounts hacked - and they do this multiple times a day.
@licquorice I said that back in messages 6 & 9.
Sadly the odds are the same on each random attempt, and each attempt is independent, so the success rate is determined.
As a aside what I did find interesting from the barrage of probably 1000-1500 texts I got before they got into my account was that the BT generated pins had A LOT of duplicate pin numbers and separated across requests. This also surprised me a lot.
But the success rate isn't determined if not every number is utilised.
@WSH no, I'm saying something slightly different.
@licquorice Yes, the same thought had occurred to me...but I'd already given up by then. As indeed I'm going to now.
I guess that once the correct combination of numbers had been found that email address can then be used for hoax, spam etc messages
Thanks. Yes it has subsided now