Live data from Hacker News

T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

wsj.com

61–70 of 138 posts

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#61
post #43

Earlier quoted context omitted.

how on earth do you have 3 lines with unlimited data for 32 a month?

this is crazy what you pay in america, in europe the cheapest unlimited t-mobile plan goes with 90€

Tmobile is technically different companies in Europe and US, although Tmobile in Europe owns 43% of Tmobile US, and interestingly, the German government owns 32% of Tmobile Europe.

https://en.wikipedia.org/wiki/T-Mobile_US

https://en.wikipedia.org/wiki/Deutsche_Telekom

Tmobile is also widely considered to be the worst of the 3 US mobile networks (Verizon is considered to have the best coverage, then ATT, then Tmobile). Their pricing reflects that too, as Verizon is the most expensive, then ATT, then Tmobile.

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#62
post #26

Earlier quoted context omitted.

...but what do you do with 10 lines?

Have a large family or a small business? My wife's immediate family is 9 adults, 6 of whom are all on the same cell plan because it's cheap and convenient for everyone involved. If everyone gets along, there's not a whole lot of downside here.

The biggest security risk with being on someone else's mobile network account in the US is that someone else has control of your phone number.

These days, access to your phone number basically constitutes verification and authorization from you for many things, including transfers of money.

I control the phone lines for myself, my wife, my mom, one of my cousins, and my sister. But I would not give someone other than my wife control of mine or my wife's phone number, no matter how much I trust them.

>If everyone gets along, there's not a whole lot of downside here.

Everyone always gets along, until they do not.

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#63
post #23

Earlier quoted context omitted.

From the article "John Binns, a 21-year-old American who moved to Turkey a few years ago" I'm assuming it is the Turkey thing, probably counting on that to be a significant barrier. Yes they have extradition but I've also heard that Turkish authorities are quite amenable to bribes as well.

> I've also heard that Turkish authorities are quite amenable to bribes as well. If the dude is banking on this, the major issue is that the Turkish authorities may be quite amenable to bribes from anyone indeed. Subsequently, my wager is that both TMobile and many among the 50M whose details were stolen have far deeper pockets than hacker exhibit A. In other words, the dude must be absolutely certain that government…

What would Tmobile or those whose details have already been leaked have to gain from going after the guy now? The information is already out there, is it not?

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#65

Earlier quoted context omitted.

So what you are saying is that the overcall cost of doing business with tmobile (both monetary and your personal data being public) justifies the convenience?

It's not so much the convenience as the problems other carriers bring. T-Mobile has no security, and lousy coverage, and is technically incompetent, but they're fairly honest and customer-friendly. I could tell a horror story from Verizon about a multi-thousand-dollar roaming bill from someone I knew, from Google about being completely locked out of a phone number forever from another person, and lots of others. Pick…

TMobile actually has good coverage now. Since the Sprint merger they have started rolling out 5g 600mhz on the old Nextel network. I'm in a rural area and as of last year I can get 90mbps down with TMobile. Verizon and ATT are like 5 and get swamped on weekends.

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#66

Earlier quoted context omitted.

What do you consider a background in compsci? A few years in the industry? Because my degree is in Management Information Systems (MIS), but I've done troubleshooting on both performance problems of the O(n^5) variety and problems of the "not covered in the requirements document" variety... Not sure what else I need to understand, say, memory bounds-checking problems or firewall/ACL configuration problems. EDIT: expa…

What’s MIS?

Management Information Systems. A "business oriented" computer degree. They were popular in the 80s as an alternative to comp. sci. They focus on how to use databases and spreadsheets, and other analytical and management systems. In those days, "decision support" software was a big thing. Is MIS still a thing anymore?

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#67

Earlier quoted context omitted.

I'm sure it's both. As in, much of what they did spend likely went to snake oil salesmen. I've met lots of security consultants who did not have backgrounds in math or compsci.

> I've met lots of security consultants who did not have backgrounds in math or compsci. My experience both working at and with higher end consultancies is that there is no correlation whatsoever between those degrees and any particular consultant’s competency. Some of the best people I’ve worked alongside have been college dropouts and Religion majors.

Likewise, I've never found any correlation between those degrees and security improvements delivered by consultants. Honestly, the best security consultants I know of are essentially con men (and women!) who have devoted their amateur psychological instincts to good. You can apply all the best tech but without organizational change it won't last. On the flip side if you bring organizational change to adopt security in depth as a value then even substandard tech can serve the purpose. In that vain, the best security consultants (meaning someone hired temporarily for their expertise – not a long term employee hired by renewable contract) are those who can imbue leadership with the vision of their organization as one that benefits financially from security as a cultural value. I'm not sure who did this for Apple but they are a good example of a company that has benefited from a reputation earned by truly valuing security instead of trying to merely make sure everything is secure.

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#68
post #41

Earlier quoted context omitted.

I'm sure it's both. As in, much of what they did spend likely went to snake oil salesmen. I've met lots of security consultants who did not have backgrounds in math or compsci.

> I'm sure it's both. As in, much of what they did spend likely went to snake oil salesmen. I've met lots of security consultants who did not have backgrounds in math or compsci. I'm going to bet that they did have qualified engineers, because I like to assume the best in people, but I also assume that those engineers may not have been able to make the changes they want to. In my experience in big companies, corporat…

You can't easily "bolt on" security to a massive internal ecosystem of insecure projects that has built up over the years. If I had to guess, I would anticipate the software T-Mobile is running includes a lot of legacy that hasn't been fully maintained. If they don't spend the cash to retain developers who built these projects or to keep them maintained, it means there's nobody around who really knows the codebase. And that means funding the little security edge cases is going to be nearly impossible, particularly for an external contractor with a few months.

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#69

Earlier quoted context omitted.

> I've also heard that Turkish authorities are quite amenable to bribes as well. If the dude is banking on this, the major issue is that the Turkish authorities may be quite amenable to bribes from anyone indeed. Subsequently, my wager is that both TMobile and many among the 50M whose details were stolen have far deeper pockets than hacker exhibit A. In other words, the dude must be absolutely certain that government…

What would Tmobile or those whose details have already been leaked have to gain from going after the guy now? The information is already out there, is it not?

It could even simply be a matter of harrassment by the Turkish government because existing bribes are suddenly, say, insufficient. Under penalty of prison, of course.

Unless he gets a cushy gov't cybersec job from all this, which is another angle I have just considered.

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#70
post #66

Earlier quoted context omitted.

What’s MIS?

Management Information Systems. A "business oriented" computer degree. They were popular in the 80s as an alternative to comp. sci. They focus on how to use databases and spreadsheets, and other analytical and management systems. In those days, "decision support" software was a big thing. Is MIS still a thing anymore?

I got a degree in it in the early 2010s (technically my university called it Information Science and Technology)

I just say "business and computers and how they go together" when explaining it.

Post reply on HN