In practice, what are the barriers to adoption which folks are seeing, and what can we do about it?
Hackers claim they breached T-Mobile more than 100 times in 2022
131–140 of 342 posts
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#132> T-Mobile declined to answer questions about what it may be doing to beef up employee authentication. But Nicholas Weaver, a researcher and lecturer at University of California, Berkeley’s International Computer Science Institute, said T-Mobile and all the major wireless providers should be requiring employees to use physical security keys for that second factor when logging into company resources. > “These breaches…
I think why regulation hasn’t happened is because the computer industry has changed so quickly. Two-factor auth wasn’t even a commonly accepted best practice two decades ago. And regulation takes a while to create and put into practice and with the rate things are going, by the time regulation has been out in place, the current best practices will have changed. Whereas writing regulation on building bridges is easy b…
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#133Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#134Earlier quoted context omitted.
Have you missed how much spam a regular phone was getting regularly? Doesn’t seem difficult to regather such an operation to do SIM swap attacks. With AI the mechanisms are even easier.
I have no idea what you are talking about here. SIM swap and spam texts/calls are entirely different issues.
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#135The security situation with these companies shows no signs of improving. My hot take is to make many forms of hacking legal so long as the hacker reports their findings to the government. Let's have a free for all where every white hat and grey hat hacker gets to test the security of all companies, no permission from the companies required. Otherwise, it's only black hats that get to do the hacking, and they won't te…
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#136> Phish T-Mobile employees for access to internal company tools, and then convert that access into a cybercrime service that could be hired to divert any T-Mobile user’s text messages and phone calls to another device. If they are doing all this through phishing and aren't being as successful with other networks there's some serious issue that's being overlooked. It's unclear from the article if this is due to traini…
> But there's still a large number of sites and services that rely on SMS. I avoid using my actual phone number whenever possible and use a Google Voice number. Hacking Google Voice would require hacking my actual Google account instead of just tricking someone at the phone company.
I do too. Sadly there are a number of sites/orgs that require you to use a mobile number. I don't really understand why.
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#137I was a victim of this last October and November on a T-Mobile number. This is what occurred: - My Gmail account was compromised - My Amazon account was compromised In Gmail, they added a filter to hide any shipping or customer service messages from Amazon. In Amazon, every other day, they placed an order for a ~500 USD GoPro device, delivered to an address in NYC. This address changed with every order. Both password…
Interesting... I had something similar happen to me, with minimal outward, acute damage (e.g., running up bills on random credit cards). It is reasonable to assume my entire identity is compromised. Sorry this happened. How do you know T-Mobile was the entry point, and not say, Google (e.g., Google Chrome, Google Ads)? What type of phone did you have (e.g., Android or iPhone)? What is your browser and Search Engine o…
I used an iPhone, Safari mobile, Google search engine.
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#138I was a victim of this last October and November on a T-Mobile number. This is what occurred: - My Gmail account was compromised - My Amazon account was compromised In Gmail, they added a filter to hide any shipping or customer service messages from Amazon. In Amazon, every other day, they placed an order for a ~500 USD GoPro device, delivered to an address in NYC. This address changed with every order. Both password…
It’s hardly a second factor if it can be used to entirely replace the primary one.
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#139Earlier quoted context omitted.
No 2FA on your GMail? Any idea how G and A were compromised, password reuse?
Probably SMS as a 2FA option on Gmail, which is the real problem. Once you add your Yubikey and set up TOTP as a backup, you need to go back and delete SMS as a 2FA option. Had gmail been configured correctly, the SIM swap would have far less serious.
I used to work tech support for cell phone providers, and while we were trained about fraud, the nature of the industry low wages, high turnover, makes this a security flaw that financial institutions should not risk.
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#140" Initial carriers that have signed up to Open Gateway are América Móvil, AT&T, Axiata, Bharti Airtel, China Mobile, Deutsche Telekom, e& Group, KDDI, KT, Liberty Global, MTN, Orange, Singtel, Swisscom, STC, Telefónica, Telenor, Telstra, TIM, Verizon and Vodafone. "
Link: https://techcrunch.com/2023/02/26/mobile-carriers-team-up-wi...