Live data from Hacker News

Hackers claim they breached T-Mobile more than 100 times in 2022

krebsonsecurity.com

161–170 of 342 posts

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#161
My approach to this is to use a google voice phone number where all SMS get sent to email. The voice account and the gmail account are the same google account which is secure by hardware 2FA yubikey login. I have a cell phone with an entirely different number that I use for non-2FA things so if it gets compromised i'm OK. I do access that email from that phone, so I suppose i'm a bit vulnerable to targeted phone theft, but SIM swapping shouldn't be a problem, I don't think?

In the opinion of HN is this the most secure way to do it while still allowing me to use services that force SMS based 2FA (almost everything) ?

Is there a better way?

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#163
post #84

Earlier quoted context omitted.

I think why regulation hasn’t happened is because the computer industry has changed so quickly. Two-factor auth wasn’t even a commonly accepted best practice two decades ago. And regulation takes a while to create and put into practice and with the rate things are going, by the time regulation has been out in place, the current best practices will have changed. Whereas writing regulation on building bridges is easy b…

That’s assuming you regulate a very specific thing versus the end goal. To me the appropriate regulation is to find a way to cause real harm to T-Mobile when they are breached. When repeated like this or if done through effectively negligence, then they shouldn’t be allowed to be in business anymore. We gotta stop the tiny fines.. jail, billions of dollars in fines, remove their business license… something large need…

One way to do so would be to make it so wireless companies can lose access to spectrum as a consequence of customer data breaches. Let someone else who can keep customer data secure have it instead.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#164

Earlier quoted context omitted.

TMobile seems to be particularly bad right now, but Verizon and AT&T aren’t necessarily good. The weak link is usually retail or channel. TMobile is in a high growth phase, so I’d hazard to guess they are more disorganized. Switching to Verizon may reduce exposure, but they have their own similar issues - an aggressively dumb carrier employee is capable of almost anything.

As sad as it is to write this, Apple corporate lines are Verizon - though they also have ATT available if you need it or have a preference. I only say this as I don’t know of any major corporation who picks TMO as their company lines. All this to say, I trust ATT and Verizon slightly more than T-Mobile

The corporate accounts are a little different, but people like retail employees can do damage. You can control SIMs out of band in some cases.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#165

Earlier quoted context omitted.

> those instances _should_ be easy to trace and prosecute I suspect that the employees aren't merely doing a sim swap attack with their work login credentials. Like you say, they'd clearly get fired/prosecuted for that. Instead, I suspect criminal X buys a nice thing delivered to employee Y's house. Then, criminal X phones the helpdesk repeatedly till they get connected to employee Y during working hours. Then, they…

On darknet diaries the stories told are a little more straightforward. They just walk in to the store, steal a tablet out of the manager's hands, run away with it, and make all the changes they can with the logged-in session until corporate locks out the device.

People sell this as a service and supposedly have numbers on how long from a provider tablet is stolen until the device gets locked out. If I remember correctly T-mobile was/is considered to have the "longest" time from when the device is stolen, there for the most valuable.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#166
post #96

Earlier quoted context omitted.

No 2FA on your GMail? Any idea how G and A were compromised, password reuse?

Probably SMS as a 2FA option on Gmail, which is the real problem. Once you add your Yubikey and set up TOTP as a backup, you need to go back and delete SMS as a 2FA option. Had gmail been configured correctly, the SIM swap would have far less serious.

I can use my phone number for 2FA and/or as a recovery phone number. Would you advise to remove it from both places or just from 2FA?

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#167

Earlier quoted context omitted.

I think it has failed because the industry is moving way faster than most people can keep up. Even your average developer isn’t going to be aware of security changes in the industry to know what’s important or not. It’s going to be even less likely they someone not in engineering to remotely know what’s important or not. Security professionals know but do you seek out a cardiologist first before you ask your GP? Prob…

"People" don't need to keep up, the internal controls team needs to keep up, and it's possible to staff such a team with people who know how to mitigate phishing attacks when you are one of the largest corporate targets of phishing by volume on the earth.

They do because they are the ones hiring.

If you’re trying to decide between electricians but you know nothing about electrical jobs, you’re going to be unable to make any meaningful decision. You’re just going to pick the one that sounds the best.

Heck, you could be using the same mediocre electrician for years and even recommend it to friends because you still have no clue about the workmanship.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#168

The security situation with these companies shows no signs of improving. My hot take is to make many forms of hacking legal so long as the hacker reports their findings to the government. Let's have a free for all where every white hat and grey hat hacker gets to test the security of all companies, no permission from the companies required. Otherwise, it's only black hats that get to do the hacking, and they won't te…

Lack of knowledge of vulnerability is not the limiting factor in this case. All a "free for all" would do in this case is make more noise in which malicious actors can hide in the logs.

Are you saying they're aware of all these vulnerabilities? Why don't they fix them? Can one of the wealthiest companies in the nation not fix vulnerabilities they're already aware of? What is the limiting factor here? Competence?

My conspiracy theory is that my idea will never be implemented because it would expose the "job creator" class to an objective measure of their competence, and they would not fare well. Headlines like "97% of US organizations are incapable of building secure systems" would not be fun.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#169

Earlier quoted context omitted.

SMS 2FA is a security risk! I used to work tech support for cell phone providers, and while we were trained about fraud, the nature of the industry low wages, high turnover, makes this a security flaw that financial institutions should not risk.

How is SMS a security risk? As far as I know, SMS is closely tied to a person's identity, especially 'know your customer' regulations. I'm curious how it's a security risk; as far as I know they have to be unique, which is good

Simjacking.

https://en.wikipedia.org/wiki/SIM_swap_scam

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#170
post #137

Earlier quoted context omitted.

Interesting... I had something similar happen to me, with minimal outward, acute damage (e.g., running up bills on random credit cards). It is reasonable to assume my entire identity is compromised. Sorry this happened. How do you know T-Mobile was the entry point, and not say, Google (e.g., Google Chrome, Google Ads)? What type of phone did you have (e.g., Android or iPhone)? What is your browser and Search Engine o…

I assumed it was T-Mobile after I wiped the phone and had the follow-up incident where a verification code via SMS was successfully verified. I used an iPhone, Safari mobile, Google search engine.

SMS in unencrypted, and Google SE has been compromised for much if not all of 2022. From what I can tell the issue persists. I officially reported it in December, and again in January, and again in February. Pretty wild, TBH. Think about the number of services that have Google SE and Ads integration. Makes me nauseous.

Did you happen to report to Apple and Google (for documentation)?

Post reply on HN