Live data from Hacker News

T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

wsj.com

41–50 of 138 posts

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#41

"A booming industry of cybersecurity consultants, software suppliers and incident-response teams have so far failed to turn the tide against hackers and identity thieves who fuel their businesses by tapping these deep reservoirs of stolen corporate data." Sure, blame the consultants with their "booming industry". I'm sure T-Mobile spent adequate amounts of money on securing their data, hired all the best people, and…

I'm sure it's both. As in, much of what they did spend likely went to snake oil salesmen. I've met lots of security consultants who did not have backgrounds in math or compsci.

> I'm sure it's both. As in, much of what they did spend likely went to snake oil salesmen. I've met lots of security consultants who did not have backgrounds in math or compsci.

I'm going to bet that they did have qualified engineers, because I like to assume the best in people, but I also assume that those engineers may not have been able to make the changes they want to.

In my experience in big companies, corporate bureaucracy and a complete unwillingness to change processes or systems is usually a bigger hinderance to security than the skill level of consultants/engineers.

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#42
post #41

Earlier quoted context omitted.

I'm sure it's both. As in, much of what they did spend likely went to snake oil salesmen. I've met lots of security consultants who did not have backgrounds in math or compsci.

> I'm sure it's both. As in, much of what they did spend likely went to snake oil salesmen. I've met lots of security consultants who did not have backgrounds in math or compsci. I'm going to bet that they did have qualified engineers, because I like to assume the best in people, but I also assume that those engineers may not have been able to make the changes they want to. In my experience in big companies, corporat…

Worse, the "upper management" will assume it was a talent / investment problem since "they sunk so much money into security". Oh that darn booming industry.

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#43

Been a T-Mobile customer for ages. Sim swaps are too easy. 2 factor is a joke. This is like the 3rd time my data has been lifted. But I stay with them, why? Because I have 3 free lines, unlimited everything, for $32 a month. They have crazy phone trade in deals from time to time, T-Mobile tuesday usually nets me 15c off per gallon at shell. Am I happy that they keep getting hacked? Absolutely not, but I'm happy prett…

how on earth do you have 3 lines with unlimited data for 32 a month?

this is crazy what you pay in america, in europe the cheapest unlimited t-mobile plan goes with 90€

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#44
post #41

Earlier quoted context omitted.

> I'm sure it's both. As in, much of what they did spend likely went to snake oil salesmen. I've met lots of security consultants who did not have backgrounds in math or compsci. I'm going to bet that they did have qualified engineers, because I like to assume the best in people, but I also assume that those engineers may not have been able to make the changes they want to. In my experience in big companies, corporat…

Worse, the "upper management" will assume it was a talent / investment problem since "they sunk so much money into security". Oh that darn booming industry.

"To think we paid those security consultants so much money to protect our completely unencrypted and exposed database and we still got hacked.

And they had the nerve to suggest we replace this unencrypted database, which an old legacy system needs entirely open root access to with something secure for an eye watering bill - we don't hire security consultants to replace our legacy systems, we pay them to stop unauthorised people accessing the big pile of data we leave in the open.

Get the gall - they even wanted us to change the interface between our two big legacy systems because it was just a CSV file which contained all our sensitive data on it. Wimps! Especially as we told them they could do anything to make our systems secure, as long as they didn't touch those legacy systems."

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#46

Earlier quoted context omitted.

how on earth do you have 3 lines with unlimited data for 32 a month?

I pay about $25 a month for unlimited everything with T Mobile.

How? I have limited data and pay $65? Part of a larger family plan?

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#47
post #3

Everyone's security is awful, as the penalty for failure is less than the expense required to make it secure. Until the former becomes higher the latter will guarantee insecurity rules.

Does the basic security scanning the hacker was doing costs hundreds of millions for big companies? Because that's the fines some big companies are getting:

https://www.csoonline.com/article/3410278/the-biggest-data-b...

or at least tens of millions in the EU thanks to GDPR:

https://www.enforcementtracker.com/

We understand it's nothing compared to their profits but is it nothing compared to the cost of basic security?

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#48
post #23

What I don't understand is why the hacker (whose full name is used in the article - alias?) is being public about this? Shit security or not, they made a clear cut black hat move purely for money. Or I suppose the other factor is fame/infamy. Pretty sure there are at least a few pissed off hackers among those 50M people who would want to track this person down digitally and pull something as retaliation.

From the article "John Binns, a 21-year-old American who moved to Turkey a few years ago" I'm assuming it is the Turkey thing, probably counting on that to be a significant barrier. Yes they have extradition but I've also heard that Turkish authorities are quite amenable to bribes as well.

> I've also heard that Turkish authorities are quite amenable to bribes as well.

If the dude is banking on this, the major issue is that the Turkish authorities may be quite amenable to bribes from anyone indeed. Subsequently, my wager is that both TMobile and many among the 50M whose details were stolen have far deeper pockets than hacker exhibit A.

In other words, the dude must be absolutely certain that government corruption can only go well for him. In the US, he'd "only" go to prison if the system wants to make an example out of him. In a place where anyone can be bribed to do anything, the sky is the limit.

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#49
post #3

Everyone's security is awful, as the penalty for failure is less than the expense required to make it secure. Until the former becomes higher the latter will guarantee insecurity rules.

Everyone always talks about making penalties more severe for data leaks. I have to wonder what the consequences of that would be. Bankrupting your competitor might become as easy as paying a few bitcoins to a foreign mercenary. I think better security and encryption protocols need to be developed that mitigate the severity of a single leak. Without more compartmentalization of data and more control put into the hands…

> Bankrupting your competitor might become as easy as paying a few bitcoins to a foreign mercenary.

This would result in insurance policies to guarantee against that outcome. Those policies in turn would introduce both costs and practices across industries that would improve the security of all the insured (and indirectly, their customers).

Unlike hiring a Rainmaker to look nice for the C-suite, imposing these costs would make sure that there's effective mitigations. Just like safety matters for your car, it would start to matter for your software.

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#50

"A booming industry of cybersecurity consultants, software suppliers and incident-response teams have so far failed to turn the tide against hackers and identity thieves who fuel their businesses by tapping these deep reservoirs of stolen corporate data." Sure, blame the consultants with their "booming industry". I'm sure T-Mobile spent adequate amounts of money on securing their data, hired all the best people, and…

I had to manually change the urls in their site to opt-out of some data sharing a couple months ago.

Something like that getting shipped to prod... yeah, you have the D team building tech at tmobile. So we should collectively be shocked if their codebase isn't a leaky sieve.

Post reply on HN