Are there any kind of legal consequences for this in the US? Or is the reigning attitude basically 'if customers voluntarily gave the company that information, that's on them'?
T-Mobile: Breach Exposed SSN/DOB of 40M+ People
71–80 of 282 posts
Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People
#72> Why do I suggest this? Many online services allow users to reset their passwords just by clicking a link sent via SMS, and this unfortunately widespread practice has turned mobile phone numbers into de facto identity documents. Which means losing control over your phone number thanks to an unauthorized SIM swap or mobile number port-out, divorce, job termination or financial crisis can be devastating.
Hmmm, I get why he says this, but what is the practical scenario here? We remove phone numbers from accounts after we make them? But doesn't that just mean we disable 2FA, making our accounts less secure and therefore more likely to be compromised by other means?
Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People
#73> And he causes all, the small and the great, and the rich and the poor, and the free men and the slaves, to be given a mark on their right hand or on their forehead, and he provides that no one will be able to buy or to sell, except the one who has the mark, either the name of the beast or the number of his name.
Additionally, politicians who pay lip service to these beliefs have an extremely strong and malleable voting bloc. It's a little crazy that a modern society is held hostage by such superstitions, but that's the way it's been. Fortunately, we just this year crossed beneath the 50% church membership threshold and the numbers continue to drop.
Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People
#74>Can we please have this in the US? No, because a significant amount of people in the USA think any kind of federal identification system is the "mark of the beast" from the biblical book of Revelation.
Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People
#75>Can we please have this in the US? No, because a significant amount of people in the USA think any kind of federal identification system is the "mark of the beast" from the biblical book of Revelation.
Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People
#76As usual they don't say how this was accomplished. They call it "sophisticated" but it probably was just stupid or lazy, which is very common in most corporate hacks. Big companies don't really care much about security since it costs money and rarely causes much trouble to your stock price and exec compensation. The people who suffer are those whose data is compromised and have no idea it happened.
https://twitter.com/damienmiller/status/1427195852011937797
Damien Miller @damienmiller Looks like T-Mobile hasn't updated the OpenSSH installation (and thus probably neither OS) since 2014. SHA256 has been the default hostkey fingerprint since the openssh 6.8 release in 2015
Retweeted: https://twitter.com/Jeremy_Kirk/status/1427144723731402756 Jeremy Kirk @Jeremy_Kirk The person who claims to have compromised T-Mobile says the company misconfigured a gateway GPRS support node that was apparently used for testing. It was exposed to the internet. That allowed the person to eventually pivot to the LAN. Proof screenshot supplied.
Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People
#77With the frequency of these breaches, it feels like we are moving to a post-security world where SSNs and DOBs are simply public information. Would that really be such a bad thing? Both seem completely replaceable as authentication steps.
Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People
#78Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People
#79Earlier quoted context omitted.
Most European countries have some sort of strong online authentication with two factor, so it is doable.
For example?
Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People
#80As usual they don't say how this was accomplished. They call it "sophisticated" but it probably was just stupid or lazy, which is very common in most corporate hacks. Big companies don't really care much about security since it costs money and rarely causes much trouble to your stock price and exec compensation. The people who suffer are those whose data is compromised and have no idea it happened.