Earlier quoted context omitted.
I'm not entirely sure, this seems to be US only, we were talking about T-Mobile Austria.
At the end of the day, it's the same company.
TMobile confirms they store passwords in plaintext, don't see why it's a problem
21–30 of 45 posts
Re: TMobile confirms they store passwords in plaintext, don't see why it's a problem
#22"Well, what if your infrastructure gets breached and everyone’s password is published in plaintext to the whole wide world?" "What if this doesn't happen because our security is amazingly good? ^Käthe" This is begging for it.
I can’t fault a low-level employee too much for enthusiastically defending their company. I can’t expect someone at that level to know about sound development practices. What’s often lacking though is a clear path for reporting security issues to people such as this representative. They don’t have a process to flag something for the security team.
Re: TMobile confirms they store passwords in plaintext, don't see why it's a problem
#23Earlier quoted context omitted.
At the end of the day, it's the same company.
That doesn't mean they have the same account management setup
Re: TMobile confirms they store passwords in plaintext, don't see why it's a problem
#24One possibility could be that they store only the first four characters plaintext, and keep a hash of the whole password (which is also bad). I wonder how this feature came to be? What were those meetings like?
Re: TMobile confirms they store passwords in plaintext, don't see why it's a problem
#25Earlier quoted context omitted.
That doesn't mean they have the same account management setup
According the T-Mobile USA CEO, "US customer care reps can't see passwords, nor are they stored in plain text." https://twitter.com/bkurbs/status/982373984695042048
Re: TMobile confirms they store passwords in plaintext, don't see why it's a problem
#26Whats stopping someone from creating a list of what strings trslate to each hash
Re: TMobile confirms they store passwords in plaintext, don't see why it's a problem
#27Earlier quoted context omitted.
According the T-Mobile USA CEO, "US customer care reps can't see passwords, nor are they stored in plain text." https://twitter.com/bkurbs/status/982373984695042048
That's not true, though, because there is a "phone PIN" that you give to an operator when you need their help, and you can get it txted to you using a special SMS command.
After a valid pin has been entered or X invalid tries by the customer service agent the customer needs to request another support pin.
Now this doesn’t doesn’t mean that the transmission of SMS is 100% secure but as they operate the network they could be in a much better place to validate that a request came from and was delivered to a phone and sim on their network (if the customer is on network and not roaming, but would be a bit of a shit customer support experience if you could only get support on network).
Just saying that the one time, limited lifespan support code system can be done securely so let’s not throw them under the bus just yet.
Edit: Using support pins delivered to the phone should only be treated as proof of being in possession of the sim and not proof of being the account holder.
Re: TMobile confirms they store passwords in plaintext, don't see why it's a problem
#28One possibility could be that they store only the first four characters plaintext, and keep a hash of the whole password (which is also bad). I wonder how this feature came to be? What were those meetings like?
Is this TMobile USA? I worked in engineering when they were still Voicestream Wireless. We were acquired by Deutsche Telekom and rebranded as TMobile. We had virtually no interaction with the European "T-Mobile."
Every T-Mobile (including the US one) is owned by Deutsche Telekom, but most of its subsidiaries are named differently. For example, Macedonian is called "Makedonski Telekom" instead of "T-Mobile Macedonia".
Re: TMobile confirms they store passwords in plaintext, don't see why it's a problem
#29"Well, what if your infrastructure gets breached and everyone’s password is published in plaintext to the whole wide world?" "What if this doesn't happen because our security is amazingly good? ^Käthe" This is begging for it.
“Excuse me? Do you have any idea how telecommunication companies work? Do you know anything about our systems? But I'm glad you have the time to share your view with us. ^Käthe” And doubling down as well, that’s a bold strategy.
I know, and it ain’t fucking pretty. Plaintext passwords (and stupid customer service) are just the tip of the iceberg.
Telcos are right up there with internet-connected industrial control systems when it comes to security and the huge fallouts of a breach.
Re: TMobile confirms they store passwords in plaintext, don't see why it's a problem
#30LunarPages, a large web hosting company, does this too and doesn't see why it's a problem. It's terrifying.