Live data from Hacker News

AT&T employees were bribed to install phone unlocking malware on company network

geekwire.com

101–110 of 157 posts

Re: AT&T employees were bribed to install phone unlocking malware on company network

#101
post #14

1.) How is unlocking a phone "malware"? Isn't the lock malware, and the unlocking serves the owner of the device? Calling it malware reeks of regurgitating AT&T propaganda. 2.) How did this "deprive AT&T of the stream of payments it was owned under the customers’ service contracts and installment plans."? A phone getting unlocked doesn't void a contract, so those customers are still on the hook.

It sounds like he had to install malware in the call center / AT&T remote location so he could get the unlock codes remotely. "Malware" is probably not the correct term. Once the phone is ported to another network, the original provider is basically SOL, contract or no.

"unauthorized software" is better but this was malicious relative to AT&T.

Re: AT&T employees were bribed to install phone unlocking malware on company network

#102
post #79
post #27

Earlier quoted context omitted.

A contract was violated when these phones were unlocked. In return for a locked phone the buyer received a subsidy from AT&T on the cost of the hardware. I don't want people to violate contracts with me, why should I recognize someone as a hero just because I don't like the contract? To be absolutely clear, I don't like locked phones, either, so I always buy non-carrier-locked devices and it means I pay the full, uns…

Contracts are violated all the time - it's called efficient breach. Most of the time, there are no penalties either. If AT&T overcharges you, and you don't notice - they just take your money without consequence. If you can get away with efficient breach of contract, do it. As a former lawyer who write contracts all day, I will give you a virtual high five.

Sure it may be legal but is it whats morally good? If someone / your employer entered into a contract with you to pay you for your legal services for a year and then efficiently breached the terms would you give them a high five and be fine with it? In your example, would you give AT&T a high five for efficiently breaching their contract and taking money from a subscriber?

Also I'm not sure if you're using the right terminology. From Wex, Efficient breach: A breach of contract in which the breaching party finds it cheaper to pay damages than to perform under the contract. [1]

You're not paying them when you unlock your phone out of contract so it wouldn't be efficient breach. It's just breach of contract. Also as you know it's not really breach of contract or not until a judge says so, so you can't just call contract violations that happen all the time an efficient breach.

I have a bit of legal education from years ago and I understand that there are many things that are legally "right" but there are other things to consider too.

[1]https://www.law.cornell.edu/wex/efficient_breach

Re: AT&T employees were bribed to install phone unlocking malware on company network

#104

Earlier quoted context omitted.

What contract? Most of these contracts have terms for canceling early. Like a fee to cover the remaining cost of the phone. After that point, it's their phone and I don't see a problem with someone using their property on another network.

When your contract is up they will unlock the phone for you.

Most carriers will force you to pay for this privilege - certainly all the ones I've ever had dealings with.

Re: AT&T employees were bribed to install phone unlocking malware on company network

#105

> “Now he will be held accountable for the fraud and the lives he has derailed.” Whoa there. What? Yes, he's committed a crime and should be held accountable for that. But.. Who's lives has he derailed? If I was to accept a bribe to commit a crime, nobody is derailing my life but me - to say anything else suggests a level of intelligence bordering on inability to understand and take responsibility for my actions. Can…

If you profit off of a violent crime by making that crime more profitable, I believe you are morally culpable in that crime.

This person made muggings more profitable, and profited from it. If there was even one concussion from a mugging that otherwise wouldn't have happened, I would say that's a life derailed. Not provable, but likely.

Re: AT&T employees were bribed to install phone unlocking malware on company network

#106

When a phone is “locked”, what does that entail? Is there a list of IMEIs somewhere that carriers check against when phones connect to their network, or is it something on the handset itself? If it’s software on the phone, surely it’s possible to hack it on the phone itself?

simlock. War between hackers and carriers/handset manufacturers has been raging since before the Mitnick days (Motorola firmware hack).

For example mikeselectricstuff (hackaday readers will immediately recognize the name https://www.youtube.com/user/mikeselectricstuff/videos , he is known among other things for Reverse Engineering the iPod Nano 6 screen and hacking FLIR E4 Thermal Imaging Camera to full resolution) has been making a living cracking GSM handset firmware in the nineties.

Re: AT&T employees were bribed to install phone unlocking malware on company network

#107
post #70

Earlier quoted context omitted.

Same with Comcast, if not worse. For some reason their systems appear to take forever to load a customer account. One could probably find and pull a physical file of a user account faster in the pre-computer days out of a huge room full of wall to wall filing cabinets. I am not sure if it's ineptness or they pretend to take long to make support calls as frustrating as possible.

The trick I've found with Comcast is to go to their offices. The in-person support people have always been able to deal with whatever I was there for quickly and satisfactorily.

I don't want to, as a consumer I'd like to get decent customer service in a manner that isn't directly inconveniencing to either me or, even, the company. I don't demand that reps show up at my door, but it is seriously annoying how far Comcast will go out of their way refusing to help you.

Re: AT&T employees were bribed to install phone unlocking malware on company network

#108
post #31

Earlier quoted context omitted.

The contract sucks shit that's why

> The contract sucks shit that's why All those people were free to buy unsubsidized phones elsewhere. They knew exactly what they were getting into when they signed up.

I would argue that that your latter assertion is not the case, at least not here in the US. When I got my first cellphone in the mid-00s, you bought your phone on an installment plan from the carrier as part of the service contract, the purchase installments were rolled up with your and service fees, and that's the way the world worked, regardless of which carrier you chose. Bringing your own device was not a thing.

It wasn't until later that I learned that cellphones could exist independent of their carrier networks and be unlocked therefrom; that one (in theory) could purchase a phone somewhere else, and then bring it to the the carrier of one's choice to be configured to interface with that network. And I only learned of that fact because I am nerd who likes to learn as much as he can about anything he becomes involved in.

Most people aren't nerds or have nerd-like tendencies. Most people simply want a magic rectangle so they can have Snapchat and Twitter in their pocket. The carriers do little to advertise the fact purchasing phones independently is even an option. So I'd say, no, most people don't know what they're getting into when they sign up.

And lest you say that said terms are right there in the contract, while true, be honest, when was the last time you carefully read and understood all 40-pages of the EULA when you have a more pressing problem to solve? I suspect even you commonly simply click the "I Agree" to get that damn boilerplate out of the way so you can Buy The Thing already.

Re: AT&T employees were bribed to install phone unlocking malware on company network

#109
post #79
post #27

Earlier quoted context omitted.

A contract was violated when these phones were unlocked. In return for a locked phone the buyer received a subsidy from AT&T on the cost of the hardware. I don't want people to violate contracts with me, why should I recognize someone as a hero just because I don't like the contract? To be absolutely clear, I don't like locked phones, either, so I always buy non-carrier-locked devices and it means I pay the full, uns…

Contracts are violated all the time - it's called efficient breach. Most of the time, there are no penalties either. If AT&T overcharges you, and you don't notice - they just take your money without consequence. If you can get away with efficient breach of contract, do it. As a former lawyer who write contracts all day, I will give you a virtual high five.

Most cell unlocking websites work this exact way, it's a huge network of insiders.

The "unlock marketplaces" is the place where people buy and sell online and offline unlock https://www.google.com/search?q=gsm+unlock+forum

Re: AT&T employees were bribed to install phone unlocking malware on company network

#110

Earlier quoted context omitted.

> The contract sucks shit that's why All those people were free to buy unsubsidized phones elsewhere. They knew exactly what they were getting into when they signed up.

Counterpoint: carriers don't always make it easy to unlock your phone even if they allow you to do so as per the contract. It can involve lots of back and forth with clueless monkeys in their customer service department. There's also the issue of legitimately buying/acquiring a phone, finding it to be locked and having no idea which carrier it is locked to nor how to go about getting it unlocked. It isn't an easy pro…

This is a tertiary issue, but for carriers using locked bootloaders unlock them when you unlock your phone to go to another carrier? If not, then the device that's bought and paid for is still not wholly owned by the customer.

I've never owned a phone with a bootloader I couldn't unlock myself (unofficially or otherwise), so I don't know if this is the case or not.

Post reply on HN