Live data from Hacker News

Hackers claim they breached T-Mobile more than 100 times in 2022

krebsonsecurity.com

121–130 of 342 posts

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#121
The security situation with these companies shows no signs of improving.

My hot take is to make many forms of hacking legal so long as the hacker reports their findings to the government. Let's have a free for all where every white hat and grey hat hacker gets to test the security of all companies, no permission from the companies required. Otherwise, it's only black hats that get to do the hacking, and they won't tell anyone when the find a vulnerability.

Everyone wins except for the companies who will be embarrassed they can't build a secure system to save their life. And they won't be able to legally bully someone for pressing F12 anymore.

This is important, it's a national security issue. Extreme measures like this are justified.

Some hacks, such as DDoS attacks might have to remain illegal. But otherwise, unless your proven to be stealing and selling data, let there be strong legal protections for those who responsibly report vulnerabilities.

And this is practical too. With vulnerability bounties you can solve the problem just by throwing money at it. But bounties can't be an opt-in thing, the companies who need them most are not opting-in.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#122
post #84
post #8

> T-Mobile declined to answer questions about what it may be doing to beef up employee authentication. But Nicholas Weaver, a researcher and lecturer at University of California, Berkeley’s International Computer Science Institute, said T-Mobile and all the major wireless providers should be requiring employees to use physical security keys for that second factor when logging into company resources. > “These breaches…

I think why regulation hasn’t happened is because the computer industry has changed so quickly. Two-factor auth wasn’t even a commonly accepted best practice two decades ago. And regulation takes a while to create and put into practice and with the rate things are going, by the time regulation has been out in place, the current best practices will have changed. Whereas writing regulation on building bridges is easy b…

> Two-factor auth wasn't even a commonly accepted best practice two decades ago.

Maybe, had you said three decades? But not two. It was already mature by then.

Two decades ago was 2003. Even consumer banking was online, and in many countries exclusively 2FA.

I've worked the banking space then and we absolutely had smart cards. Military and defense had them everywhere. Proprietary solutions had already gone away replaced by PC/SC. NT 4.0SP6 had support out of the box, because it was already a hard requirement for many customers two and a half decade ago.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#124
post #26

Earlier quoted context omitted.

> But there's still a large number of sites and services that rely on SMS. I avoid using my actual phone number whenever possible and use a Google Voice number. Hacking Google Voice would require hacking my actual Google account instead of just tricking someone at the phone company.

why do you think that? Presumably Google Voice uses a phone company downstream, which means if that company is hacked they can reassign your number to someone else and thus you have the classic SIM jacking attack.

Which phone company does the hacker call to trick into believing they are Google?

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#125
Some of the comments here seem to argue that creating legislation that demands basic security baselines will not get the job done. In fact in a recent interview[1] Jen Easterly (head of CISA gov) fell into the same trap (assuming because she didn't want to upset tech company lobby groups) so her message was reduced to shouting into the void (asking vendors "please be-good"):

> Addressing these issues requires a long-term approach and not simply a new set of regulations or industry standards. Easterly said it will require the leaders of technology companies to focus explicitly on building safer products, provide transparency into their development and manufacturing processes, and an understanding that the burden of safety should not fall solely (or even mainly) on customers.

I'm right now struggling to get a bunch of US IoT companies to agree on a very basic set of security standards that would allow more interoperability. All we're asking are basic best practice to anyone working in security (e.g. ETSI 303 645). And the reason why I'm struggling is because in the EU these baselines are becoming the law as of 1st Aug. 2024 with the Radio Equipment Directive (RED). And in addition these same kind of guardrails will also become law with the Cybersec Resilience Act in 2025 expanded to the cloud and mobile apps. So this thing is coming and the US which has a lot better standards (thanks to NIST but lacks legalization due to power of lobby groups) looks like a total laggard here to a point where it becomes embarrassing.

Nobody in their right minds would argue there are unreasonable provisions in these proposals for RED (or the CRA). Yet all the US based vendors who do not sell into EU markets shout "bloody murder".

And it's hilarious how they're all grandstanding about "how dare the communist EU is telling business how to innovate".

Legislation works. Begging vendors to come up with better controls by themselves will not.

Anyone who has spent even a single day working in security in a company where security isn't part of their core value proposition (or isn't _the_ product) will know the only way to enforce even the most basic security and safety controls[2] is by legislation.

You want a unified charging standard for EV? Make it the law!

You want a single type of charger for all phones? Make it the law.

You want your coding standards to meet guidelines for functional safety? Make them law.

You want to eliminate OWASP Top-10 from production code? Make it the law.

[1] https://duo.com/decipher/strong-security-has-to-be-a-standar...

[2] entirely related: The Humble History of the Crash Test Dummy https://www.motorbiscuit.com/the-humble-history-of-the-crash...

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#126
post #65

I was a victim of this last October and November on a T-Mobile number. This is what occurred: - My Gmail account was compromised - My Amazon account was compromised In Gmail, they added a filter to hide any shipping or customer service messages from Amazon. In Amazon, every other day, they placed an order for a ~500 USD GoPro device, delivered to an address in NYC. This address changed with every order. Both password…

[flagged]

If this scammer thought they were a high value target, I imagine they would have gone bigger than buying $500 GoPros.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#127
post #115

Earlier quoted context omitted.

[flagged]

> BTW - give me some of that big-swinging-credit-balls you seem to gotts... 15 * 500 = 7,500 USD. Having a steady job should put that within reach.

[flagged]

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#128
post #65

I was a victim of this last October and November on a T-Mobile number. This is what occurred: - My Gmail account was compromised - My Amazon account was compromised In Gmail, they added a filter to hide any shipping or customer service messages from Amazon. In Amazon, every other day, they placed an order for a ~500 USD GoPro device, delivered to an address in NYC. This address changed with every order. Both password…

Scary, this just convinced me to turn off text-based 2FA and only have Google Auth App (+ backup keys). Thank you.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#129
post #65

I was a victim of this last October and November on a T-Mobile number. This is what occurred: - My Gmail account was compromised - My Amazon account was compromised In Gmail, they added a filter to hide any shipping or customer service messages from Amazon. In Amazon, every other day, they placed an order for a ~500 USD GoPro device, delivered to an address in NYC. This address changed with every order. Both password…

Interesting... I had something similar happen to me, with minimal outward, acute damage (e.g., running up bills on random credit cards). It is reasonable to assume my entire identity is compromised. Sorry this happened.

How do you know T-Mobile was the entry point, and not say, Google (e.g., Google Chrome, Google Ads)? What type of phone did you have (e.g., Android or iPhone)? What is your browser and Search Engine on your smartphone?

Thanks!

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#130
I worked for TMobile for 4 days in 2021. I don't usually apply to big companies but money was tight because pandemic and I needed a job quick. I was assigned to work on the config server (think in-house developed consul or etcd) and it was awful. "If this specific config value is being set by Service A then what is actually written should be twice the given value, but if Service B is reading the value, return 1/3 of the value as an HTTP form body instead of JSON." By Thursday I got a call about a new position and I left so quick that the recruiters black listed me. TMobile getting hacked is a "when" not an "if"
Post reply on HN