Live data from Hacker News

T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

wsj.com

31–40 of 138 posts

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#31
post #7

It would be nice to be able to open these accounts without providing PII, so that it would be harder to attack specific users, and breaches would not be so damaging to customers. This US trend of requiring government-issued ID for even routine transactions (like phone service) that aren’t ID-related is insane and dangerous.

Anyone know of a provider that doesn't mandate storing this info? I understand they want to know your credit to open an account so need your pii to get credit info, but does any cell provider not store it after that? I tried to get tmobile to delete mine and they won't so I'm open to switching to any post-paid service that does.

Not post-paid.

If you want privacy, you need to be more serious than that. Mint mobile prepaid (no personal info) on a device you bought outright in cash. Obviously, no one should know that phone number; you should do all interactions through your publicly known VOIP number that's forwarded. That phone shouldn't be turned on any time you're near home; that should be done with a separate home iPad or the like. And no traffic should ever happen outside of a VPN...

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#33

"A booming industry of cybersecurity consultants, software suppliers and incident-response teams have so far failed to turn the tide against hackers and identity thieves who fuel their businesses by tapping these deep reservoirs of stolen corporate data." Sure, blame the consultants with their "booming industry". I'm sure T-Mobile spent adequate amounts of money on securing their data, hired all the best people, and…

I'm sure it's both. As in, much of what they did spend likely went to snake oil salesmen. I've met lots of security consultants who did not have backgrounds in math or compsci.

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#34

Been a T-Mobile customer for ages. Sim swaps are too easy. 2 factor is a joke. This is like the 3rd time my data has been lifted. But I stay with them, why? Because I have 3 free lines, unlimited everything, for $32 a month. They have crazy phone trade in deals from time to time, T-Mobile tuesday usually nets me 15c off per gallon at shell. Am I happy that they keep getting hacked? Absolutely not, but I'm happy prett…

So what you are saying is that the overcall cost of doing business with tmobile (both monetary and your personal data being public) justifies the convenience?

It's not so much the convenience as the problems other carriers bring. T-Mobile has no security, and lousy coverage, and is technically incompetent, but they're fairly honest and customer-friendly.

I could tell a horror story from Verizon about a multi-thousand-dollar roaming bill from someone I knew, from Google about being completely locked out of a phone number forever from another person, and lots of others.

Pick your liability.

On the whole, I found the risk of data theft from T-Mobile to be the lesser of the evils.

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#37

Been a T-Mobile customer for ages. Sim swaps are too easy. 2 factor is a joke. This is like the 3rd time my data has been lifted. But I stay with them, why? Because I have 3 free lines, unlimited everything, for $32 a month. They have crazy phone trade in deals from time to time, T-Mobile tuesday usually nets me 15c off per gallon at shell. Am I happy that they keep getting hacked? Absolutely not, but I'm happy prett…

how on earth do you have 3 lines with unlimited data for 32 a month?

I pay about $25 a month for unlimited everything with T Mobile.

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#38
post #3

Everyone's security is awful, as the penalty for failure is less than the expense required to make it secure. Until the former becomes higher the latter will guarantee insecurity rules.

Everyone always talks about making penalties more severe for data leaks. I have to wonder what the consequences of that would be. Bankrupting your competitor might become as easy as paying a few bitcoins to a foreign mercenary.

I think better security and encryption protocols need to be developed that mitigate the severity of a single leak. Without more compartmentalization of data and more control put into the hands of users, leaks of these massive, un-encrypted databases appear inevitable.

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#39

"A booming industry of cybersecurity consultants, software suppliers and incident-response teams have so far failed to turn the tide against hackers and identity thieves who fuel their businesses by tapping these deep reservoirs of stolen corporate data." Sure, blame the consultants with their "booming industry". I'm sure T-Mobile spent adequate amounts of money on securing their data, hired all the best people, and…

I'm sure it's both. As in, much of what they did spend likely went to snake oil salesmen. I've met lots of security consultants who did not have backgrounds in math or compsci.

Probably memorized a checklist and passed a multiple choice tests or two to become certified.

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#40

Been a T-Mobile customer for ages. Sim swaps are too easy. 2 factor is a joke. This is like the 3rd time my data has been lifted. But I stay with them, why? Because I have 3 free lines, unlimited everything, for $32 a month. They have crazy phone trade in deals from time to time, T-Mobile tuesday usually nets me 15c off per gallon at shell. Am I happy that they keep getting hacked? Absolutely not, but I'm happy prett…

how on earth do you have 3 lines with unlimited data for 32 a month?

I have 8 lines in total, three of them free, plus a free unlimited tablet plan.
Post reply on HN