Live data from Hacker News

Hackers claim they breached T-Mobile more than 100 times in 2022

krebsonsecurity.com

131–140 of 342 posts

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#131
No silver bullet but many of these types of attacks would be mitigated, or at least made much more expensive and difficult for the attackers, if we had wider adoption of Yubikey, Webauthn etc. type otp solutions which are more resistant to phishing, keyloggers etc.

In practice, what are the barriers to adoption which folks are seeing, and what can we do about it?

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#132
post #84
post #8

> T-Mobile declined to answer questions about what it may be doing to beef up employee authentication. But Nicholas Weaver, a researcher and lecturer at University of California, Berkeley’s International Computer Science Institute, said T-Mobile and all the major wireless providers should be requiring employees to use physical security keys for that second factor when logging into company resources. > “These breaches…

I think why regulation hasn’t happened is because the computer industry has changed so quickly. Two-factor auth wasn’t even a commonly accepted best practice two decades ago. And regulation takes a while to create and put into practice and with the rate things are going, by the time regulation has been out in place, the current best practices will have changed. Whereas writing regulation on building bridges is easy b…

Aviation industry can introduce new regulation fast. One example would be reinforced cockpit doors. Prompted by events in September 2001, new standards published four months later (January 2002), expected to be completed fifteen months after that (April 2003).

https://avalon.law.yale.edu/sept11/faa_001.asp

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#134

Earlier quoted context omitted.

Have you missed how much spam a regular phone was getting regularly? Doesn’t seem difficult to regather such an operation to do SIM swap attacks. With AI the mechanisms are even easier.

I have no idea what you are talking about here. SIM swap and spam texts/calls are entirely different issues.

If it's scalable to mass call a good chunk of the US population, I'm sure it's scalable to mass call providers to socially engineer a SIM swap.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#135

The security situation with these companies shows no signs of improving. My hot take is to make many forms of hacking legal so long as the hacker reports their findings to the government. Let's have a free for all where every white hat and grey hat hacker gets to test the security of all companies, no permission from the companies required. Otherwise, it's only black hats that get to do the hacking, and they won't te…

Lack of knowledge of vulnerability is not the limiting factor in this case. All a "free for all" would do in this case is make more noise in which malicious actors can hide in the logs.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#136
post #26

> Phish T-Mobile employees for access to internal company tools, and then convert that access into a cybercrime service that could be hired to divert any T-Mobile user’s text messages and phone calls to another device. If they are doing all this through phishing and aren't being as successful with other networks there's some serious issue that's being overlooked. It's unclear from the article if this is due to traini…

> But there's still a large number of sites and services that rely on SMS. I avoid using my actual phone number whenever possible and use a Google Voice number. Hacking Google Voice would require hacking my actual Google account instead of just tricking someone at the phone company.

> I avoid using my actual phone number whenever possible and use a Google Voice number.

I do too. Sadly there are a number of sites/orgs that require you to use a mobile number. I don't really understand why.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#137
post #65

I was a victim of this last October and November on a T-Mobile number. This is what occurred: - My Gmail account was compromised - My Amazon account was compromised In Gmail, they added a filter to hide any shipping or customer service messages from Amazon. In Amazon, every other day, they placed an order for a ~500 USD GoPro device, delivered to an address in NYC. This address changed with every order. Both password…

Interesting... I had something similar happen to me, with minimal outward, acute damage (e.g., running up bills on random credit cards). It is reasonable to assume my entire identity is compromised. Sorry this happened. How do you know T-Mobile was the entry point, and not say, Google (e.g., Google Chrome, Google Ads)? What type of phone did you have (e.g., Android or iPhone)? What is your browser and Search Engine o…

I assumed it was T-Mobile after I wiped the phone and had the follow-up incident where a verification code via SMS was successfully verified.

I used an iPhone, Safari mobile, Google search engine.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#138
post #65

I was a victim of this last October and November on a T-Mobile number. This is what occurred: - My Gmail account was compromised - My Amazon account was compromised In Gmail, they added a filter to hide any shipping or customer service messages from Amazon. In Amazon, every other day, they placed an order for a ~500 USD GoPro device, delivered to an address in NYC. This address changed with every order. Both password…

They were able to reset your Google password using only the simjacked phone? Or was the password the same as the T-mobile one as well?

It’s hardly a second factor if it can be used to entirely replace the primary one.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#139
post #96

Earlier quoted context omitted.

No 2FA on your GMail? Any idea how G and A were compromised, password reuse?

Probably SMS as a 2FA option on Gmail, which is the real problem. Once you add your Yubikey and set up TOTP as a backup, you need to go back and delete SMS as a 2FA option. Had gmail been configured correctly, the SIM swap would have far less serious.

SMS 2FA is a security risk!

I used to work tech support for cell phone providers, and while we were trained about fraud, the nature of the industry low wages, high turnover, makes this a security flaw that financial institutions should not risk.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#140
One random factoid I notice is that AWS and Microsoft just announced launch of Open Gateway. Noticeably missing from that list of Telecom Providers is... T-Mobile. I'm sure it's mere coincidence, albeit a noticeable coincidence.

" Initial carriers that have signed up to Open Gateway are América Móvil, AT&T, Axiata, Bharti Airtel, China Mobile, Deutsche Telekom, e& Group, KDDI, KT, Liberty Global, MTN, Orange, Singtel, Swisscom, STC, Telefónica, Telenor, Telstra, TIM, Verizon and Vodafone. "

Link: https://techcrunch.com/2023/02/26/mobile-carriers-team-up-wi...

Post reply on HN