Live data from Hacker News

Hackers claim they breached T-Mobile more than 100 times in 2022

krebsonsecurity.com

31–40 of 342 posts

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#32
post #8

> T-Mobile declined to answer questions about what it may be doing to beef up employee authentication. But Nicholas Weaver, a researcher and lecturer at University of California, Berkeley’s International Computer Science Institute, said T-Mobile and all the major wireless providers should be requiring employees to use physical security keys for that second factor when logging into company resources. > “These breaches…

You assume that regulation can just make security magically happen.

I see no reason to assume that premise to be correct in practice. It's not like the US Government hasn't been breached countless times or had Supreme Court opinions leaked; and it's not like corporations that really tried and should be examples of best practice haven't also been breached. Also, what law can prevent insider attacks? There's already plenty of laws making that illegal.

There's no law that just "makes security happen" - and, actually, I would be fundamentally opposed to such a law because it turns security into a simple matter of compliance. "We're SCA compliant, therefore we're good!" And technology changes way too much - a security law that was written 10 years ago would be a disaster today. See South Korea's Banking Security laws for an example - they basically enshrined ActiveX in their law with roll-your-own-crypto to this day. And we know now that was a trash idea but nobody wants to take the blame for upsetting the security standards. https://palant.info/2023/01/02/south-koreas-online-security-... and https://www.nytimes.com/2022/07/08/business/korea-internet-e...

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#33

Might it be time for the US government to step in using eminent domain, seize the company and merge it into a different provider? Are other providers more secure or do we just hear about T-Mobile the most? Who should take over T-Mobile? [Edit] The more I think about this, perhaps another path to resolution would be to remove limited liability protections from companies that repeatedly put their customers at risk, esp…

And then we'd be down to what, two wireless carries in the US? AT&T already tried to acquire/merge with T-Mobile some years ago but it didn't go through. I forget why, but probably due to antitrust issues. And wasn't Sprint just acquired/merged with not long ago, by T-Mobile IIRC?

And then we'd be down to what, two wireless carries in the US?

I think you are correct. I don't like the idea of making a giant-bell yet once again but I also don't see a way to correct T-Mobiles obvious cavalier and brazen incompetence. Fines? Companies just factor that into the cost of doing business. Threat of losing their FCC license? I think collusion between business and government would drag that fight out for decades and probably even exacerbate the problem. March their leaders through town with a shame-nun? I don't know what would get real results quickly. Tack on some bigger fiduciary liabilities since phones are used to authenticate bank transactions?

Perhaps if some powerful political leaders had nasty secrets revealed or lost money as a result of these hacks there might be action but that is a big if. That might never happen and that also assumes there is proper attribution.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#34
post #21

Was thinking about moving a line to Google Fi for this reason. I know they just resell T-Mobile bandwidth, but would they provide better account level security? Is it common for Google Fi customers to get SIM swapped?

yup https://www.bleepingcomputer.com/news/security/google-fi-dat...

my friend had google fi and was caught in this, among other things they had their instagram taken over. scary few days. thankfully their roommate works at meta...

I think the only way to be really safe is to use one of the smaller MVNOs and never ever ever reveal who your carrier is

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#35
post #8

> T-Mobile declined to answer questions about what it may be doing to beef up employee authentication. But Nicholas Weaver, a researcher and lecturer at University of California, Berkeley’s International Computer Science Institute, said T-Mobile and all the major wireless providers should be requiring employees to use physical security keys for that second factor when logging into company resources. > “These breaches…

You assume that regulation can just make security magically happen. I see no reason to assume that premise to be correct in practice. It's not like the US Government hasn't been breached countless times or had Supreme Court opinions leaked; and it's not like corporations that really tried and should be examples of best practice haven't also been breached. Also, what law can prevent insider attacks? There's already pl…

I'm not calling for regulation on general security outcomes. I'm talking specifically about access controls on sensitive and highly privileged systems that have ripple impacts to consumer security, which should already be obvious best practice.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#36

Earlier quoted context omitted.

You assume that regulation can just make security magically happen. I see no reason to assume that premise to be correct in practice. It's not like the US Government hasn't been breached countless times or had Supreme Court opinions leaked; and it's not like corporations that really tried and should be examples of best practice haven't also been breached. Also, what law can prevent insider attacks? There's already pl…

I'm not calling for regulation on general security outcomes. I'm talking specifically about access controls on sensitive and highly privileged systems that have ripple impacts to consumer security, which should already be obvious best practice .

You assume that T-Mobile didn't try and just fail miserably, or repeatedly fail to insider attacks. If it was multiple insiders, the systems could be perfect technically and completely useless practically. We also don't know what the similar statistics for Verizon or AT&T or any other global carrier are for comparison.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#37

You know, I’m starting to become slightly more serious about switching carriers solely based on how terrible it would be to experience SMS/Call diverting of my number. While I use a yubikey, OTP (where possible), and unique passwords…there’s still places where I have no choice and my number is my auth (or stupidly a reset option). I genuinely am happy with TMO service in the US, and frankly abroad it’s excellent…but…

TMobile seems to be particularly bad right now, but Verizon and AT&T aren’t necessarily good.

The weak link is usually retail or channel. TMobile is in a high growth phase, so I’d hazard to guess they are more disorganized. Switching to Verizon may reduce exposure, but they have their own similar issues - an aggressively dumb carrier employee is capable of almost anything.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#38
post #30

Might it be time for the US government to step in using eminent domain, seize the company and merge it into a different provider? Are other providers more secure or do we just hear about T-Mobile the most? Who should take over T-Mobile? [Edit] The more I think about this, perhaps another path to resolution would be to remove limited liability protections from companies that repeatedly put their customers at risk, esp…

What should not have happened is the Sprint T-Mobile merger. Like when Wells Fargo bought the failed bank (forget which one) after 2008, Wells Fargo went from a reliable company to all kinds of suspect things going on with our account. So far T-Mobile has been fine for us but we are seeing some marketing things floating around suggesting the Sprint influence might be having a negative impact on T-Mobile. I miss John…

Wachovia[0], perhaps?

[0] https://www.federalreserve.gov/newsevents/testimony/alvarez2...

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#39
post #9
post #3

[flagged]

You didn't read the article. This isn't about a data leak, it's about being able to intercept SMS for any T-Mobile phone number.

You are right. I was speaking generally about the fact that my data and “identity” can be stolen without any penalty. There is zero incentive to T-Mobile to prevent things like this from happening in the future. There is no financial incentive for them. They won’t lose any customers, and won’t be fined. Why invest any amount in security with these sets of incentives in place?

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#40

Earlier quoted context omitted.

I'm not calling for regulation on general security outcomes. I'm talking specifically about access controls on sensitive and highly privileged systems that have ripple impacts to consumer security, which should already be obvious best practice .

You assume that T-Mobile didn't try and just fail miserably, or repeatedly fail to insider attacks. If it was multiple insiders, the systems could be perfect technically and completely useless practically. We also don't know what the similar statistics for Verizon or AT&T or any other global carrier are for comparison.

I'm not assuming anything, I'm pointing out a failure of self-regulation given the TTPs listed in the original article, which are distinct from fully insider-supported attacks, should not happen.

There is obvious, direct, and destructive customer impact here.

Edit: actually I know people working in security roles for T-Mobile, and I am sure they or their sister teams are trying.

Post reply on HN