Live data from Hacker News

T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

wsj.com

131–138 of 138 posts

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#131
If you received the text about the account hack as I did, it had this at the end of the message:

“Learn more about practices that keep your account secure and general recommendations for protecting yourself: “

When on a support call with them, they claimed that my account was fine and I had nothing to worry about. And then the last thing they tell you is to improve your security.

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#132

"A booming industry of cybersecurity consultants, software suppliers and incident-response teams have so far failed to turn the tide against hackers and identity thieves who fuel their businesses by tapping these deep reservoirs of stolen corporate data." Sure, blame the consultants with their "booming industry". I'm sure T-Mobile spent adequate amounts of money on securing their data, hired all the best people, and…

I don't doubt that T-Mobile could have done more, but it's also frustrating to see this trope that spending more money on security is some type of silver bullet. It's not. I've been in security for over a decade. I currently work at a FAANG with nearly unlimited security budget. Previously I worked at another major tech company with nearly unlimited security budget. Before that I was a consultant and consulted at com…

> I don't doubt that T-Mobile could have done more, but it's also frustrating to see this trope that spending more money on security is some type of silver bullet. It's not.

So true. A problem is that "spending money on security" is so nearly always a synonym for increasing the infosec budget under the CISO. Which is useful, yes, but only a partial solution. A bigger ROI would be to spend it on developers who are experts in security and building a culture that cares. But even in enterprise security companies (most of my career), product security is so often seen as a checklist that infosec will take care of, not a core engineering competency.

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#133

Earlier quoted context omitted.

This makes no sense at all---you're implying that the bad guys somehow have a monopoly on innovation and effectiveness, when in reality, there is just more upside for them to steal sensitive info than there is downside for companies to protect it. If T-Mobile's latest data breach led to them getting fined, say, $5 billion, I promise you it would be the last.

It would be the last for T-Mobile because it would end T-Mobile. But it wouldn't be the last breach ever. I could give $5 billion to my FAANG right now and I bet we'd still be breached (hell, I'm pretty sure we already have that budget in my FAANG's security department). The US DoD already has a cyber security budget of $10 billion, and they still get breached. You underestimate the amount that these companies care a…

> I've sat in boardrooms with CEOs telling us they were willing to pay whatever it takes to increase their security (and they put their money where their mouth is, too). They still get breached.

Money flows (often) freely but it's not enough. I worked at one place where the CISO was very aware that security needs to be designed into the product ground up. Later a new CISCO came in who thought that security can be achieved merely by purchasing every security scanner on the market and sit back to bask in perfect security. Needless to say security was far worse with the latter one.

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#134
post #26

Earlier quoted context omitted.

Have a large family or a small business? My wife's immediate family is 9 adults, 6 of whom are all on the same cell plan because it's cheap and convenient for everyone involved. If everyone gets along, there's not a whole lot of downside here.

The biggest security risk with being on someone else's mobile network account in the US is that someone else has control of your phone number. These days, access to your phone number basically constitutes verification and authorization from you for many things, including transfers of money. I control the phone lines for myself, my wife, my mom, one of my cousins, and my sister. But I would not give someone other than…

...so you're saying your mom and cousin are doing it, but it's a bad thing that people shouldn't do?

Like, you just provided the counter-example to your own point while making your point.

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#135
post #74

Does anyone have a good solution for sites that only support SMS 2FA? I'm mostly using Google Voice for 2FA right now, but I'm iffy on tying access to my entire life to a Google account. Ideally I'd like a dirt-cheap, just-for-2FA phone number from a provider that's got decent security (specifically regarding SIM swapping).

I have a voip.ms number left over from another project, and it does support SMS although I've had fairly crappy luck getting it to work for services that need it for 2FA.

Seems like there's no good option, as VOIP numbers are fairly secure but ironically not allowed by many companies for SMS.

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#136

Blame the victim. The reality is, it’s all about incentives. He is going to make a few million. If their security were great they’d still have gotten hacked. Everyone who knows anything about computers knows, where there’s a will there’s a way. You cannot stop a determined hacker. Full stop. The problem is there are great incentives and not enough deterrents. Bitcoin. This will only get worse until the public decides…

This is a really odd take to me. No, you may not get every single thing right, and if someone is really determined then they might get through. But does that mean you shouldn't put the effort in to make that as difficult as possible? Of course not. What you're saying is essentially the equivalent of saying "If someone had a bulldozer they could smash through the wall into my house anyway, so I'm going to stop locking…

I’d rather live in a world where people don’t lock their doors. That world existed not long ago. What you see as normal and acceptable differs from my ideal.

The question I pose to you: how much is enough in a world with constantly escalating threat? I’d submit that locking doors is a reaction to somewhat static threat. Digital crime is accelerating due to changes in the feasibility and incentives for the criminal- more exploits and digital currencies that make it easy and low risk for the criminal. The more crime, the more value and “adoption” of the digital currencies, the more motivation and less risk for criminal. Not at all like locking your door. It’s a treadmill that will ultimately destroy the fabric of society.

We once lived in a world without door locks. We can choose our future. That’s the opposite of fatalism.

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#137

Earlier quoted context omitted.

I'm sure it's both. As in, much of what they did spend likely went to snake oil salesmen. I've met lots of security consultants who did not have backgrounds in math or compsci.

> I've met lots of security consultants who did not have backgrounds in math or compsci. My experience both working at and with higher end consultancies is that there is no correlation whatsoever between those degrees and any particular consultant’s competency. Some of the best people I’ve worked alongside have been college dropouts and Religion majors.

Sorry for the late reply, but I chose the term "background" over "degree" for this very reason.

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#138

Earlier quoted context omitted.

This is a really odd take to me. No, you may not get every single thing right, and if someone is really determined then they might get through. But does that mean you shouldn't put the effort in to make that as difficult as possible? Of course not. What you're saying is essentially the equivalent of saying "If someone had a bulldozer they could smash through the wall into my house anyway, so I'm going to stop locking…

I’d rather live in a world where people don’t lock their doors. That world existed not long ago. What you see as normal and acceptable differs from my ideal. The question I pose to you: how much is enough in a world with constantly escalating threat? I’d submit that locking doors is a reaction to somewhat static threat. Digital crime is accelerating due to changes in the feasibility and incentives for the criminal- m…

You can want to live in that world all you like. But it's not anywhere close to a reflection of reality.
Post reply on HN