Hackers claim they breached T-Mobile more than 100 times in 2022
krebsonsecurity.com
Hackers claim they breached T-Mobile more than 100 times in 2022
1–10 of 342 posts
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#2Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#3Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#4Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#5[flagged]
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#6Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#7While I use a yubikey, OTP (where possible), and unique passwords…there’s still places where I have no choice and my number is my auth (or stupidly a reset option).
I genuinely am happy with TMO service in the US, and frankly abroad it’s excellent…but I’d be lying if every single article I see about their security breaches reminds me I may be on borrowed time myself.
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#8> “These breaches should not happen,” Weaver said. “Because T-Mobile should have long ago issued all employees security keys and switched to security keys for the second factor. And because security keys provably block this style of attack.”
At what point do we consider industry self-regulation on this a total failure? You don't need to make Yubikeys a part of every auth workflow in your corporate enterprise if there are legacy systems/integrations, but you should at least do it for the things that can change customer mobile subscription details and there can't be any excuse.
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#9[flagged]