Live data from Hacker News

Hackers claim they breached T-Mobile more than 100 times in 2022

krebsonsecurity.com

91–100 of 342 posts

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#91
post #62

Earlier quoted context omitted.

yup https://www.bleepingcomputer.com/news/security/google-fi-dat... my friend had google fi and was caught in this, among other things they had their instagram taken over. scary few days. thankfully their roommate works at meta... I think the only way to be really safe is to use one of the smaller MVNOs and never ever ever reveal who your carrier is

I've always figured I should have two numbers—one I let people know, and one for 2fa. But that's ~$20/mo and a moderate annoyance, so for now mostly just fingers crossed that eventually everywhere that matters will allow me to switch fully to authentication apps and hardware keys.

I'm getting a cell phone plan just for 2FA. It's actually a Tmobile MVNO, we'll see how it goes.

$2.50/month, RedPocket annual eBay plan.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#93
post #84
post #8

> T-Mobile declined to answer questions about what it may be doing to beef up employee authentication. But Nicholas Weaver, a researcher and lecturer at University of California, Berkeley’s International Computer Science Institute, said T-Mobile and all the major wireless providers should be requiring employees to use physical security keys for that second factor when logging into company resources. > “These breaches…

I think why regulation hasn’t happened is because the computer industry has changed so quickly. Two-factor auth wasn’t even a commonly accepted best practice two decades ago. And regulation takes a while to create and put into practice and with the rate things are going, by the time regulation has been out in place, the current best practices will have changed. Whereas writing regulation on building bridges is easy b…

I agree completely. I didn't ask why government enforced regulation hasn't happened. I asked why industry self-regulation has failed. I've worked in a regulatory/security role for a major conglomerate before.

I'm not saying I expected self-regulation to work. But, if you are in a position of customers seeing direct harm every day, it's not unreasonable to ask why there is a failure here.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#94
post #8

> T-Mobile declined to answer questions about what it may be doing to beef up employee authentication. But Nicholas Weaver, a researcher and lecturer at University of California, Berkeley’s International Computer Science Institute, said T-Mobile and all the major wireless providers should be requiring employees to use physical security keys for that second factor when logging into company resources. > “These breaches…

You assume that regulation can just make security magically happen. I see no reason to assume that premise to be correct in practice. It's not like the US Government hasn't been breached countless times or had Supreme Court opinions leaked; and it's not like corporations that really tried and should be examples of best practice haven't also been breached. Also, what law can prevent insider attacks? There's already pl…

Don't mandate them, just mandate that if you use known-deficient practices you're presumed negligent if an incident occurs. Then issue some guidelines for known best practices and known bad practices, and make it clear that using something newer/better is fine, just not using something on the "known bad" list. (For instance, best practices are to use two-factor authentication with one component being physical security; one-factor with a password is known-bad.)

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#95
post #26

> Phish T-Mobile employees for access to internal company tools, and then convert that access into a cybercrime service that could be hired to divert any T-Mobile user’s text messages and phone calls to another device. If they are doing all this through phishing and aren't being as successful with other networks there's some serious issue that's being overlooked. It's unclear from the article if this is due to traini…

> But there's still a large number of sites and services that rely on SMS. I avoid using my actual phone number whenever possible and use a Google Voice number. Hacking Google Voice would require hacking my actual Google account instead of just tricking someone at the phone company.

Bingo. Personal phone number for only friends and family. Google voice number from a nearby area code for literally everything else. It's a little more secure than my carrier.

And as an added bonus, I can automatically send all incoming google voice calls to voicemail and not have to worry about missing a family emergency. If I get a phone call on my actual cell number, it's almost guaranteed to be someone I know closely.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#96
post #65

I was a victim of this last October and November on a T-Mobile number. This is what occurred: - My Gmail account was compromised - My Amazon account was compromised In Gmail, they added a filter to hide any shipping or customer service messages from Amazon. In Amazon, every other day, they placed an order for a ~500 USD GoPro device, delivered to an address in NYC. This address changed with every order. Both password…

No 2FA on your GMail?

Any idea how G and A were compromised, password reuse?

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#97

You know, I’m starting to become slightly more serious about switching carriers solely based on how terrible it would be to experience SMS/Call diverting of my number. While I use a yubikey, OTP (where possible), and unique passwords…there’s still places where I have no choice and my number is my auth (or stupidly a reset option). I genuinely am happy with TMO service in the US, and frankly abroad it’s excellent…but…

TMobile seems to be particularly bad right now, but Verizon and AT&T aren’t necessarily good. The weak link is usually retail or channel. TMobile is in a high growth phase, so I’d hazard to guess they are more disorganized. Switching to Verizon may reduce exposure, but they have their own similar issues - an aggressively dumb carrier employee is capable of almost anything.

I think the issue is that phone companies weren’t prepared for their services to be used for such high security tasks. For many decades, your phone was just mostly for keeping up with friends and family. 2FA wasn’t even that popular until maybe in the last 10 years.

Just like how the locks we buy for our exterior doors are really weak but that’s currently fine for the status quo. You’re not going to preemptively spend money to upgrade your locks.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#98
post #49

Earlier quoted context omitted.

Thanks! Based on that article it seems that anyone who's reselling T-Mobile service would be vulnerable.

Do we know if Google Voice also uses T-Mobile? If not, might be worthwhile to switch SMS 2FA to the Voice number if a service allows voip numbers.

Google Voice isn't a wireless carrier. VoIP only.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#99
post #54

The rise of SMS as a second factor for security across the web has raised the incentive for SIM-swapping tremendously. No one should be shocked that when tech companies start outsourcing their identity verification to cell phone providers those providers come under attack.

SMS as a second factor is almost a security downgrade. Phone companies are terrible, you shouldn't be trusting them with authentication. Plus it means you can't authenticate when your phone is out of coverage. Just a bad solution that shouldn't be used. TOTP is so easy to set up that it makes no sense to use SMS, and the even better hardware keys are only slightly less convenient.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#100
post #84

Earlier quoted context omitted.

I think why regulation hasn’t happened is because the computer industry has changed so quickly. Two-factor auth wasn’t even a commonly accepted best practice two decades ago. And regulation takes a while to create and put into practice and with the rate things are going, by the time regulation has been out in place, the current best practices will have changed. Whereas writing regulation on building bridges is easy b…

I agree completely. I didn't ask why government enforced regulation hasn't happened. I asked why industry self-regulation has failed. I've worked in a regulatory/security role for a major conglomerate before. I'm not saying I expected self-regulation to work. But, if you are in a position of customers seeing direct harm every day , it's not unreasonable to ask why there is a failure here.

I think it has failed because the industry is moving way faster than most people can keep up.

Even your average developer isn’t going to be aware of security changes in the industry to know what’s important or not. It’s going to be even less likely they someone not in engineering to remotely know what’s important or not.

Security professionals know but do you seek out a cardiologist first before you ask your GP? Probably not because, being not at all trained, you have no clue about anything. And if your GP doesn’t know, you are kind of on your own.

Post reply on HN