Live data from Hacker News

T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

wsj.com

21–30 of 138 posts

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#21

What I don't understand is why the hacker (whose full name is used in the article - alias?) is being public about this? Shit security or not, they made a clear cut black hat move purely for money. Or I suppose the other factor is fame/infamy. Pretty sure there are at least a few pissed off hackers among those 50M people who would want to track this person down digitally and pull something as retaliation.

I'm going out on a limb, but based on signal from the article and actions the person has taken, I don't think they're mentally well.

I was about to comment this. He says he went public to raise awareness about allegedly being illegally detained in a "fake mental hospital". Obviously anything is possible, but that sounds a lot like he could've been legally detained and doesn't really understand the law i.e. he could've been a danger to himself or others.

His other bombastic comments to press and relatives also make him sound insecure and immature. Obviously he had to be somewhat adept and dedicated to gain access, but he didn't discover any incredible exploit here. He also takes credit for discovering a well known zero-day but admits he had nothing to do with the code for the exploit. To me that supports the idea that he hangs out in black hat circles because he wants to be one of the 'cool kids', put in the time and got lucky. I imagine the press love that because a lot of the public doesn't really know the difference.

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#22

Blame the victim. The reality is, it’s all about incentives. He is going to make a few million. If their security were great they’d still have gotten hacked. Everyone who knows anything about computers knows, where there’s a will there’s a way. You cannot stop a determined hacker. Full stop. The problem is there are great incentives and not enough deterrents. Bitcoin. This will only get worse until the public decides…

> You cannot stop a determined hacker.

Maybe not, but you can reduce the list of potential attackers from relatively average Joes to more experienced, specialised and well funded actors (such as the NSA - who would probably just issue a warrant anyway) with better security practises. It isn't ideal - someone might still access your data without your consent - but it is realistic and achievable.

> The problem is that there are great incentives and not enough deterrents.

Again, true, but that doesn't mean that the public should just live with this. It's not unreasonable to ask a company to take the security of their customers seriously and take steps to ensure that their data is secure from an attacker. There are other things that can be done: harsher penalties for companies who don't take issues like this seriously, setting out (and enforcing!) standards for security, incentivising security research, and so on. Are these suggestions achievable? Probably. Are they going to be achieved? Probably not. Are there a better ideas for solving this problem? Definitely, but I'm not smart enough to think of them. But just giving up and labelling this as an "education problem" is defeatist and doesn't help.

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#23

What I don't understand is why the hacker (whose full name is used in the article - alias?) is being public about this? Shit security or not, they made a clear cut black hat move purely for money. Or I suppose the other factor is fame/infamy. Pretty sure there are at least a few pissed off hackers among those 50M people who would want to track this person down digitally and pull something as retaliation.

From the article

"John Binns, a 21-year-old American who moved to Turkey a few years ago"

I'm assuming it is the Turkey thing, probably counting on that to be a significant barrier. Yes they have extradition but I've also heard that Turkish authorities are quite amenable to bribes as well.

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#24

Been a T-Mobile customer for ages. Sim swaps are too easy. 2 factor is a joke. This is like the 3rd time my data has been lifted. But I stay with them, why? Because I have 3 free lines, unlimited everything, for $32 a month. They have crazy phone trade in deals from time to time, T-Mobile tuesday usually nets me 15c off per gallon at shell. Am I happy that they keep getting hacked? Absolutely not, but I'm happy prett…

So what you are saying is that the overcall cost of doing business with tmobile (both monetary and your personal data being public) justifies the convenience?

When it’s really not clear if other options are any more secure then one might as well optimize for the visible features of convenience.

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#25

What I don't understand is why the hacker (whose full name is used in the article - alias?) is being public about this? Shit security or not, they made a clear cut black hat move purely for money. Or I suppose the other factor is fame/infamy. Pretty sure there are at least a few pissed off hackers among those 50M people who would want to track this person down digitally and pull something as retaliation.

I'm going out on a limb, but based on signal from the article and actions the person has taken, I don't think they're mentally well.

[deleted]

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#26
post #12

Earlier quoted context omitted.

Grandfathered "simple choice" plan with 10 lines for $160. I have upgrade to 5G phones with no problems. Not unlimited, but I never use up the data anyway. I really hope TMO takes security seriously going forward.

...but what do you do with 10 lines?

Have a large family or a small business?

My wife's immediate family is 9 adults, 6 of whom are all on the same cell plan because it's cheap and convenient for everyone involved. If everyone gets along, there's not a whole lot of downside here.

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#27

Been a T-Mobile customer for ages. Sim swaps are too easy. 2 factor is a joke. This is like the 3rd time my data has been lifted. But I stay with them, why? Because I have 3 free lines, unlimited everything, for $32 a month. They have crazy phone trade in deals from time to time, T-Mobile tuesday usually nets me 15c off per gallon at shell. Am I happy that they keep getting hacked? Absolutely not, but I'm happy prett…

how on earth do you have 3 lines with unlimited data for 32 a month?

Easy, just hack into their database and add them.

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#29
"A booming industry of cybersecurity consultants, software suppliers and incident-response teams have so far failed to turn the tide against hackers and identity thieves who fuel their businesses by tapping these deep reservoirs of stolen corporate data."

Sure, blame the consultants with their "booming industry". I'm sure T-Mobile spent adequate amounts of money on securing their data, hired all the best people, and it was all the security peoples' fault for not doing it properly.

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#30
post #28
post #10

Let's see how T-Mobile's security compares to life in prison, criminal.

I'll bite: How do you make that comparison? What are you comparing? Not being demeaning, but literally what does this sentence mean?

I'm comparing how awful T-Mobile's security is to how awful his life in prison will be for leaking the private data of millions of people.

Not an apt comparison, just a very bad joke :D

Post reply on HN