Live data from Hacker News

Hackers claim they breached T-Mobile more than 100 times in 2022

krebsonsecurity.com

181–190 of 342 posts

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#181
I believe this. I have a single credit card that I use only for our T-Mobile bill on autopay (the credit card offers insurance on my phones via this method).

About 2 months ago I noticed $15 charges very cleverly disguised as Amazon prime. The only giveaway was that it said the number was entered manually.

Everyone with T-Mobile autopay should check immediate for an Amazon prime charge that was manually entered.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#182

Earlier quoted context omitted.

SMS 2FA is a security risk! I used to work tech support for cell phone providers, and while we were trained about fraud, the nature of the industry low wages, high turnover, makes this a security flaw that financial institutions should not risk.

How is SMS a security risk? As far as I know, SMS is closely tied to a person's identity, especially 'know your customer' regulations. I'm curious how it's a security risk; as far as I know they have to be unique, which is good

Check out this article: https://krebsonsecurity.com/2023/02/hackers-claim-they-breac...

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#183
post #8

> T-Mobile declined to answer questions about what it may be doing to beef up employee authentication. But Nicholas Weaver, a researcher and lecturer at University of California, Berkeley’s International Computer Science Institute, said T-Mobile and all the major wireless providers should be requiring employees to use physical security keys for that second factor when logging into company resources. > “These breaches…

You assume that regulation can just make security magically happen. I see no reason to assume that premise to be correct in practice. It's not like the US Government hasn't been breached countless times or had Supreme Court opinions leaked; and it's not like corporations that really tried and should be examples of best practice haven't also been breached. Also, what law can prevent insider attacks? There's already pl…

> There's no law that just "makes security happen"

In another thread I proposed making white-hat hacking legally protected, even without permission from the company. If your system is constantly being tested by mostly white-hat hackers seeking their next responsible disclosure and bounty, then that's something.

Bug bounties already exist, but they're opt-in, and companies that need them the most are not opting-in. We also see the people who do things like press F12 get legally bullied[0].

Changing the laws to protect white-hats and responsible disclosure would help. This would be a law that "just makes security happen".

[0]: https://www.youtube.com/watch?v=lSsvzBV0tyI or https://arstechnica.com/tech-policy/2021/10/missouri-gov-cal...

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#184
post #138

Earlier quoted context omitted.

They were able to reset your Google password using only the simjacked phone? Or was the password the same as the T-mobile one as well? It’s hardly a second factor if it can be used to entirely replace the primary one.

Google still allows you to setup recovery phone numbers unforunately. https://support.google.com/accounts/answer/183723?hl=en&co=G... I think years ago I found my number there with no-recollection of every agreeing to it and quickly yeeted it. (You can remove the number but keep recovery email)

It's subtle with the UI but you can choose not to allow SMS by removing your phone number from Google after setting up alternative 2FA. If they don't have a number they can't sim-jack

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#185
post #137

Earlier quoted context omitted.

I assumed it was T-Mobile after I wiped the phone and had the follow-up incident where a verification code via SMS was successfully verified. I used an iPhone, Safari mobile, Google search engine.

SMS in unencrypted, and Google SE has been compromised for much if not all of 2022. From what I can tell the issue persists. I officially reported it in December, and again in January, and again in February. Pretty wild, TBH. Think about the number of services that have Google SE and Ads integration. Makes me nauseous. Did you happen to report to Apple and Google (for documentation)?

In what way is the google search engine compromised?

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#186

Do you know how expensive it is to support physical keys for a large organization? I'm not talking about the cost of the key. I'm talking about how many people lose, break, or have another problem their keys (data corruption, software issues, USB port is broken, etc). You need dedicated staff at every physical location with all the support capability to troubleshoot those issues and replace keys. Every time a key doe…

The TTPs outlined in the article could absolutely be mitigated by use of hardware keys, and this would reduce customer risk. You are right about the liability and support calculation, but that doesn't mean it's OK to shift risk to the customer because it's too expensive. It is a failure to not have implemented a physical key deployment, and it must be treated as a failure.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#187
post #65

I was a victim of this last October and November on a T-Mobile number. This is what occurred: - My Gmail account was compromised - My Amazon account was compromised In Gmail, they added a filter to hide any shipping or customer service messages from Amazon. In Amazon, every other day, they placed an order for a ~500 USD GoPro device, delivered to an address in NYC. This address changed with every order. Both password…

Scary, this just convinced me to turn off text-based 2FA and only have Google Auth App (+ backup keys). Thank you.

Another different failure point. I once broke my android phone and bought and set up a new one - only to find I can no longer access my Gmail account that I used before with my Google authenticator, so I am locked out forever from that account. I had a backup but was not able to find it. Despite knowing hundreds of contact emails (all backed up in thunderbird), account history, password history, etc - for years I have not been able to get back in.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#189
post #8

> T-Mobile declined to answer questions about what it may be doing to beef up employee authentication. But Nicholas Weaver, a researcher and lecturer at University of California, Berkeley’s International Computer Science Institute, said T-Mobile and all the major wireless providers should be requiring employees to use physical security keys for that second factor when logging into company resources. > “These breaches…

You assume that regulation can just make security magically happen. I see no reason to assume that premise to be correct in practice. It's not like the US Government hasn't been breached countless times or had Supreme Court opinions leaked; and it's not like corporations that really tried and should be examples of best practice haven't also been breached. Also, what law can prevent insider attacks? There's already pl…

In the absence of legislation (and perhaps even if/when legislation is enacted), an effective approach would be to simply hold entities to a reasonableness standard and to seek relief/damages under a common law negligence theory in lieu of a regulatory/legislative enforcement mechanism. That way, what is considered to be the industry standard (ie reasonable) changes at the pace of technology. The weak link here is quantifying individuals' damages in breaches where there is no clear injury (such as what you have in the the Amazon/GoPro example described above).

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#190
I see people jumping towards regulation, but that has the side-effect of making it even more difficult for there to be any competition against these monopolies. What we really need is legitimate competition, to enable consumers to vote with their wallet and move to a competitor that takes the security of their customer's private data seriously.
Post reply on HN