Live data from Hacker News

Hackers claim they breached T-Mobile more than 100 times in 2022

krebsonsecurity.com

171–180 of 342 posts

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#171
post #65

I was a victim of this last October and November on a T-Mobile number. This is what occurred: - My Gmail account was compromised - My Amazon account was compromised In Gmail, they added a filter to hide any shipping or customer service messages from Amazon. In Amazon, every other day, they placed an order for a ~500 USD GoPro device, delivered to an address in NYC. This address changed with every order. Both password…

> In Gmail, they added a filter to hide any shipping or customer service messages from Amazon.

I gotta admit, that's pretty clever. Crude, but effective.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#172
post #108
post #96

Earlier quoted context omitted.

No 2FA on your GMail? Any idea how G and A were compromised, password reuse?

2FA on everything. No password reused. Only similarity is both had the T-Mobile number attached to them. I initially thought only Amazon was compromised. I thought it was due to us throwing away a FireTV device (assumption: we didn't log out and de-register) that was then used to order items. And then I found they added filters to my Gmail account to hide the Amazon orders, and went into full panic mode.

Wouldn’t this still mean they cracked your gmail password? Or am I not understanding how this was executed?

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#173
post #84

Earlier quoted context omitted.

I think why regulation hasn’t happened is because the computer industry has changed so quickly. Two-factor auth wasn’t even a commonly accepted best practice two decades ago. And regulation takes a while to create and put into practice and with the rate things are going, by the time regulation has been out in place, the current best practices will have changed. Whereas writing regulation on building bridges is easy b…

Aviation industry can introduce new regulation fast. One example would be reinforced cockpit doors. Prompted by events in September 2001, new standards published four months later (January 2002), expected to be completed fifteen months after that (April 2003). https://avalon.law.yale.edu/sept11/faa_001.asp

It makes sense for a change about doors. Doors are old as time. Everyone understands how doors work. The impact of a door change is straightforward. There are relatively few moving parts involved in a self contained door (figuratively and literally).

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#175
post #65

I was a victim of this last October and November on a T-Mobile number. This is what occurred: - My Gmail account was compromised - My Amazon account was compromised In Gmail, they added a filter to hide any shipping or customer service messages from Amazon. In Amazon, every other day, they placed an order for a ~500 USD GoPro device, delivered to an address in NYC. This address changed with every order. Both password…

> In Gmail, they added a filter to hide any shipping or customer service messages from Amazon. I gotta admit, that's pretty clever. Crude, but effective.

I was about to comment the same thing. It's very simple but I don't think I would have thought of it

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#176
post #21

Was thinking about moving a line to Google Fi for this reason. I know they just resell T-Mobile bandwidth, but would they provide better account level security? Is it common for Google Fi customers to get SIM swapped?

yup https://www.bleepingcomputer.com/news/security/google-fi-dat... my friend had google fi and was caught in this, among other things they had their instagram taken over. scary few days. thankfully their roommate works at meta... I think the only way to be really safe is to use one of the smaller MVNOs and never ever ever reveal who your carrier is

As a former customer of T-Mobile, I will say that the risks go beyond SIM swapping with T-Mobile. Their website is pretty bad, and there's a lot of silly PIN-based passwords and security questions going on. Getting away from that in favor of Google's security would be a huge win.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#177

You know, I’m starting to become slightly more serious about switching carriers solely based on how terrible it would be to experience SMS/Call diverting of my number. While I use a yubikey, OTP (where possible), and unique passwords…there’s still places where I have no choice and my number is my auth (or stupidly a reset option). I genuinely am happy with TMO service in the US, and frankly abroad it’s excellent…but…

TMobile seems to be particularly bad right now, but Verizon and AT&T aren’t necessarily good. The weak link is usually retail or channel. TMobile is in a high growth phase, so I’d hazard to guess they are more disorganized. Switching to Verizon may reduce exposure, but they have their own similar issues - an aggressively dumb carrier employee is capable of almost anything.

Also consider that T-Mobile as it exists is the result of years/decades of mergers and acquisitions so they have decades of legacy and non-conforming systems. This situation is bound to cause security issues as well. I had a family member work for an MVNO that interfaced with them and this is what she saw.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#178

Earlier quoted context omitted.

> Two-factor auth wasn't even a commonly accepted best practice two decades ago. Maybe, had you said three decades? But not two. It was already mature by then. Two decades ago was 2003. Even consumer banking was online, and in many countries exclusively 2FA. I've worked the banking space then and we absolutely had smart cards. Military and defense had them everywhere. Proprietary solutions had already gone away repla…

Sure. My dad had a 2FA dongle in the 90s too But outside of government, defense and banking, who exactly was using it? It was not on the radar of the vast majority of people. Most technology takes decades to filter through the world

I had to use it in the 90s for a job I had at an automotive OEM.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#179
post #131

No silver bullet but many of these types of attacks would be mitigated, or at least made much more expensive and difficult for the attackers, if we had wider adoption of Yubikey, Webauthn etc. type otp solutions which are more resistant to phishing, keyloggers etc. In practice, what are the barriers to adoption which folks are seeing, and what can we do about it?

This is a great question.

I think the biggest barrier to adoption is lack of end user demand for the service. That is followed by people not understanding/believing the incredible increase in user experience and security. It's almost like people think it is too good to be true.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#180
Shame on T-Mobile.

That said, perhaps everybody using SMS 2FA is equally culpable (e.g. most banks). Nobody who has worked at a mobile carrier would ever think that they're ready to be high-value targets. So it's puzzling that the banks are so eager to put them in that position.

Post reply on HN