Live data from Hacker News

AT&T employees were bribed to install phone unlocking malware on company network

geekwire.com

1–10 of 157 posts

Re: AT&T employees were bribed to install phone unlocking malware on company network

#4

This is one of the problems with the cloud as well. You assume your website is well and safe but a Digital Ocean (or whatever) employee could always hack it.

That isn't cloud specific, you could say the same about anything.

Re: AT&T employees were bribed to install phone unlocking malware on company network

#5

This is one of the problems with the cloud as well. You assume your website is well and safe but a Digital Ocean (or whatever) employee could always hack it.

this is one of the problems with datacenters as well. you assume your router is well and safe but the NSA (or whatever) employee could always intercept it in transit and hack it.

Re: AT&T employees were bribed to install phone unlocking malware on company network

#7
Companies need to assume that their network is compromised.

Ignoring anything else that means they need to adopt E2E encryption for all user data (except where legally mandated to be insecure, or when the data has a fundamental need to be accessible - e.g. your bank needs to know how much money you have). Anything else, including dumbass politicians demanding magic crypto, makes your user data a valuable and achievable target.

Re: AT&T employees were bribed to install phone unlocking malware on company network

#9
post #5

This is one of the problems with the cloud as well. You assume your website is well and safe but a Digital Ocean (or whatever) employee could always hack it.

this is one of the problems with datacenters as well. you assume your router is well and safe but the NSA (or whatever) employee could always intercept it in transit and hack it.

this is the problem with offshore hosts as well. you assume the lack of an information sharing treaty and plain text writing of a law ensures the privacy of your data, but the government can just arbitrarily hand it over to the first FBI agent that asks

Re: AT&T employees were bribed to install phone unlocking malware on company network

#10
I wonder what the footprint is do the SIM hijacking, e.g. is anyone a sufficiently high enough bribe away from the type of scheme that compromises their account because it only takes 1 employee to effect it.

I've been switching to hardware keys when I'm able but it's not always feasible. I just bought a Titan key combo and you can't use most 3rd party email clients with it so that made it kind of useless to me (since Gmail's mail app isn't that great)

Post reply on HN