Live data from Hacker News

T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

wsj.com

111–120 of 138 posts

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#111

Earlier quoted context omitted.

I don't doubt that T-Mobile could have done more, but it's also frustrating to see this trope that spending more money on security is some type of silver bullet. It's not. I've been in security for over a decade. I currently work at a FAANG with nearly unlimited security budget. Previously I worked at another major tech company with nearly unlimited security budget. Before that I was a consultant and consulted at com…

> Software devs are awful at it (the amount of FAANG engineers I know that don't even understand what encryption is, or think that hashing passwords is unimportant, would blow your mind) But that's not because there aren't also lots of devs who understand security, it's because FAANG companies have purposely chosen to prioritize hiring based on leet code ability above hiring based on security knowledge. edit: This is…

Nah. First, actually being good at leet and knowing about hashing and such are not in opposition. In odd way, leet exercises makes lead to math parts of it.

And second, non leet devs are not some kind of safety panacea. The worst are people who don't care at all. Many have not heard of basics.

Third, if you actually decide that security is important and try to learn it, you will find resources are rare. There is very little of it targeted at developers. There is no shared knowledge base. There are no commonly known processes. Nothing like that.

So even if you care and try, you end up learning very little.

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#112
post #47
post #3

Everyone's security is awful, as the penalty for failure is less than the expense required to make it secure. Until the former becomes higher the latter will guarantee insecurity rules.

Does the basic security scanning the hacker was doing costs hundreds of millions for big companies? Because that's the fines some big companies are getting: https://www.csoonline.com/article/3410278/the-biggest-data-b... or at least tens of millions in the EU thanks to GDPR: https://www.enforcementtracker.com/ We understand it's nothing compared to their profits but is it nothing compared to the cost of basic securit…

Scanning is pretty inexpensive. Maintaining a complex system that passes the scans? That's something different altogether.

If I take a clunker to a mechanic, how much will it cost me to hear everything that needs fixing? About $150. But actually performing the fixes? One order of magnitude greater - and that's if I'm very, very lucky!

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#113

"A booming industry of cybersecurity consultants, software suppliers and incident-response teams have so far failed to turn the tide against hackers and identity thieves who fuel their businesses by tapping these deep reservoirs of stolen corporate data." Sure, blame the consultants with their "booming industry". I'm sure T-Mobile spent adequate amounts of money on securing their data, hired all the best people, and…

"A booming industry of cybersecurity consultants, software suppliers and incident-response teams have so far failed to turn the tide against hackers and identity thieves who fuel their businesses by tapping these deep reservoirs of stolen corporate data."

Exactly. Heaven forbid we blame the corporations whose lax security led to the stolen data in the first place. That would make advertisers unhappy.

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#114

Been a T-Mobile customer for ages. Sim swaps are too easy. 2 factor is a joke. This is like the 3rd time my data has been lifted. But I stay with them, why? Because I have 3 free lines, unlimited everything, for $32 a month. They have crazy phone trade in deals from time to time, T-Mobile tuesday usually nets me 15c off per gallon at shell. Am I happy that they keep getting hacked? Absolutely not, but I'm happy prett…

how on earth do you have 3 lines with unlimited data for 32 a month?

legacy plans

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#115
post #78

Earlier quoted context omitted.

So true. When I was a student, I aced most of my classes from math theories to ee. But took one cryptography class and everything went over my head. To this day, its hard for me to tell during hiring what makes a good security hire.

And yet, (correct me if I'm wrong), a good security person does not need to understand cryptography. He should have some basic understanding of how to apply it, but the knowledge of it's internals and the math behind it is pretty much useless.

Yeah from the outside looking in, to me the biggest requirement is one of mindset, thinking like an attacker, thinking of all the possibilities… in that sense very much like the qualities for a good QA person

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#116
post #107

Been a T-Mobile customer for ages. Sim swaps are too easy. 2 factor is a joke. This is like the 3rd time my data has been lifted. But I stay with them, why? Because I have 3 free lines, unlimited everything, for $32 a month. They have crazy phone trade in deals from time to time, T-Mobile tuesday usually nets me 15c off per gallon at shell. Am I happy that they keep getting hacked? Absolutely not, but I'm happy prett…

To clarify this is the fifth data breach in 4 years for T-Mobile. 1 in 2018, 1 in 2019, 2 in 2020.

You forgot the 2015 breach where T mobile customer's SSNs were stolen. This was the one that T-Mobile blamed on Experian and Experian said they were only holding the customer SSN's at T-Mobiles request. See:

https://money.cnn.com/2015/10/01/technology/tmobile-experian...

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#118
post #27

Earlier quoted context omitted.

how on earth do you have 3 lines with unlimited data for 32 a month?

Easy, just hack into their database and add them.

Are you accepting deals for this service?

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#119

Earlier quoted context omitted.

Probably memorized a checklist and passed a multiple choice tests or two to become certified.

It's surprisingly easy to get certified. I managed to pass the difficult-by-reputation CISSP exam without any deep knowledge of or really interest in information security. I just took the five-day crash course my company paid for and bob's your uncle, I passed the CISSP. Of course, I never actually got certified because I left the role immediately afterward and never bothered following up. Moreover, I didn't really m…

Are there any certifications that require you to solve a CTF or otherwise demonstrate understanding of the field? (Just spitballing, but maybe an oral-defence of strategy against a board of defcon panelists? Etc)

Braindump-able IT certs benefit no-one, and expecting people to have MSc degrees in infosec is elitist and very impractical.

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#120

Earlier quoted context omitted.

It's surprisingly easy to get certified. I managed to pass the difficult-by-reputation CISSP exam without any deep knowledge of or really interest in information security. I just took the five-day crash course my company paid for and bob's your uncle, I passed the CISSP. Of course, I never actually got certified because I left the role immediately afterward and never bothered following up. Moreover, I didn't really m…

Are there any certifications that require you to solve a CTF or otherwise demonstrate understanding of the field? (Just spitballing, but maybe an oral-defence of strategy against a board of defcon panelists? Etc) Braindump-able IT certs benefit no-one, and expecting people to have MSc degrees in infosec is elitist and very impractical.

Offensive Security certs (e.g. OSCP) are similar to what you're describing. The PNPT is similar too but also emulates a real-world engagement on top of just needing to root boxes.
Post reply on HN