Earlier quoted context omitted.
> BTW - give me some of that big-swinging-credit-balls you seem to gotts... 15 * 500 = 7,500 USD. Having a steady job should put that within reach.
[flagged]
Hackers claim they breached T-Mobile more than 100 times in 2022
151–160 of 342 posts
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#152I was a victim of this last October and November on a T-Mobile number. This is what occurred: - My Gmail account was compromised - My Amazon account was compromised In Gmail, they added a filter to hide any shipping or customer service messages from Amazon. In Amazon, every other day, they placed an order for a ~500 USD GoPro device, delivered to an address in NYC. This address changed with every order. Both password…
I use Google voice for everything... except my bank because they said using T-Mobile is so much more safer than Google so I had to switch back
And while on the topic of banks, most will suspend access to your online portal if you log in with a VPN. Give me a bank that allows VoIP phone numbers, VPN access, and TOTP and/or FIDO support for 2FA and I'll ditch Schwab right now.
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#153Earlier quoted context omitted.
No 2FA on your GMail? Any idea how G and A were compromised, password reuse?
Probably SMS as a 2FA option on Gmail, which is the real problem. Once you add your Yubikey and set up TOTP as a backup, you need to go back and delete SMS as a 2FA option. Had gmail been configured correctly, the SIM swap would have far less serious.
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#154Earlier quoted context omitted.
“Deep enough” would be true of any mobile carrier, to date all of these attacks are SIM swapping, with social engineering/phishing being the attack vector. Not particularly deep. Attackers would have to social engineer the MVNO directly, which is certainly easier if they have data they’ve stolen from t-mobile first, but this isn’t a “they’ll get in no matter what because they’ve pwned T-Mobile so bad” scenario.
https://www.bleepingcomputer.com/news/security/google-fi-dat... This article says that Google Fi customers were SIM swapped due to a T-Mobile breach. Even though "[t]here was no access to Google's systems or any systems overseen by Google."
> As the Google Fi data breach includes phone numbers, which can easily be linked to a customer's name, and the serial number of SIM cards, it would have made it even more convincing when contacting a mobile customer support representative.
They used the data in the breach to social engineer the Google fi reps. Attackers still needed to get through Google’s customer support system to perform the SIM swaps.
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#155Earlier quoted context omitted.
TMobile seems to be particularly bad right now, but Verizon and AT&T aren’t necessarily good. The weak link is usually retail or channel. TMobile is in a high growth phase, so I’d hazard to guess they are more disorganized. Switching to Verizon may reduce exposure, but they have their own similar issues - an aggressively dumb carrier employee is capable of almost anything.
I think the issue is that phone companies weren’t prepared for their services to be used for such high security tasks. For many decades, your phone was just mostly for keeping up with friends and family. 2FA wasn’t even that popular until maybe in the last 10 years. Just like how the locks we buy for our exterior doors are really weak but that’s currently fine for the status quo. You’re not going to preemptively spen…
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#156Earlier quoted context omitted.
Probably SMS as a 2FA option on Gmail, which is the real problem. Once you add your Yubikey and set up TOTP as a backup, you need to go back and delete SMS as a 2FA option. Had gmail been configured correctly, the SIM swap would have far less serious.
SMS 2FA is a security risk! I used to work tech support for cell phone providers, and while we were trained about fraud, the nature of the industry low wages, high turnover, makes this a security flaw that financial institutions should not risk.
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#157Earlier quoted context omitted.
Unfortunately, most carriers (except ATT & Verizon) are just T-Mobile resellers... so you might think you're not using T-Mobile but you're still affected. Even if you use ATT or Verizon, the article mentions they're also hacked and SMS intercepted often.
Honestly, I’d assume being on a MVNO carrier would actually protect you from this, as you’re simply roaming on the T-Mobile network through the carrier agreement. Even ATT and Verizon have roaming agreements. The issue is for T-Mobile direct customers, which obviously their internal systems have access to. I see no reason why T-Mobile would have access to users accounts at another company…
Of course you'll still be affected by SIM-swapping etc that just change how your number itself is routed.
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#158> T-Mobile declined to answer questions about what it may be doing to beef up employee authentication. But Nicholas Weaver, a researcher and lecturer at University of California, Berkeley’s International Computer Science Institute, said T-Mobile and all the major wireless providers should be requiring employees to use physical security keys for that second factor when logging into company resources. > “These breaches…
I think why regulation hasn’t happened is because the computer industry has changed so quickly. Two-factor auth wasn’t even a commonly accepted best practice two decades ago. And regulation takes a while to create and put into practice and with the rate things are going, by the time regulation has been out in place, the current best practices will have changed. Whereas writing regulation on building bridges is easy b…
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#159Earlier quoted context omitted.
I use Google voice for everything... except my bank because they said using T-Mobile is so much more safer than Google so I had to switch back
The prohibition against using a VoIP number for banking purposes is stupid. They already have the full battery of KYC info on me: if I want to use a VoIP number for 2FA (because they are so behind the times they don't support FIDO or even TOTP) then unless law says they cannot they need to allow it. And while on the topic of banks, most will suspend access to your online portal if you log in with a VPN. Give me a ban…
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#160Earlier quoted context omitted.
I think why regulation hasn’t happened is because the computer industry has changed so quickly. Two-factor auth wasn’t even a commonly accepted best practice two decades ago. And regulation takes a while to create and put into practice and with the rate things are going, by the time regulation has been out in place, the current best practices will have changed. Whereas writing regulation on building bridges is easy b…
> Two-factor auth wasn't even a commonly accepted best practice two decades ago. Maybe, had you said three decades? But not two. It was already mature by then. Two decades ago was 2003. Even consumer banking was online, and in many countries exclusively 2FA. I've worked the banking space then and we absolutely had smart cards. Military and defense had them everywhere. Proprietary solutions had already gone away repla…
But outside of government, defense and banking, who exactly was using it?
It was not on the radar of the vast majority of people. Most technology takes decades to filter through the world