Live data from Hacker News

Hackers claim they breached T-Mobile more than 100 times in 2022

krebsonsecurity.com

191–200 of 342 posts

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#191

Earlier quoted context omitted.

Probably SMS as a 2FA option on Gmail, which is the real problem. Once you add your Yubikey and set up TOTP as a backup, you need to go back and delete SMS as a 2FA option. Had gmail been configured correctly, the SIM swap would have far less serious.

I can use my phone number for 2FA and/or as a recovery phone number. Would you advise to remove it from both places or just from 2FA?

Remove it from both. However make sure that you have quite a lot of backups of your 2FA backup keys, and maybe even one offline backup of your seed, if you lose them, the account is gone (which is a good thing, I guess).

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#192
post #184

Earlier quoted context omitted.

Google still allows you to setup recovery phone numbers unforunately. https://support.google.com/accounts/answer/183723?hl=en&co=G... I think years ago I found my number there with no-recollection of every agreeing to it and quickly yeeted it. (You can remove the number but keep recovery email)

It's subtle with the UI but you can choose not to allow SMS by removing your phone number from Google after setting up alternative 2FA. If they don't have a number they can't sim-jack

This is one of the most important pieces of security advice that is often overlooked: remove your phone number from EVERYTHING.

You can also enable Advanced Protection[1] for your Google account, but other repeat offenders like Github will continue to allow SMS fallback to bypass 2FA if you have a phone number listed anywhere.

1. https://landing.google.com/advancedprotection/

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#193
post #54

The rise of SMS as a second factor for security across the web has raised the incentive for SIM-swapping tremendously. No one should be shocked that when tech companies start outsourcing their identity verification to cell phone providers those providers come under attack.

SMS as a second factor is almost a security downgrade. Phone companies are terrible, you shouldn't be trusting them with authentication. Plus it means you can't authenticate when your phone is out of coverage. Just a bad solution that shouldn't be used. TOTP is so easy to set up that it makes no sense to use SMS, and the even better hardware keys are only slightly less convenient.

SMS allows you to collect phone numbers which are quite good at identifying users for tracking and ad targeting though. And since most large tech companies are advertising companies (in whole or in part) it is no surprise they chose this as a second factor. Even if you try to avoid using SMS for 2FA they'll try to collect the number for account verification or recovery, with regular nags or lately go straight to extorting it out of you to continue to access purchased services or software.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#194
post #151

Earlier quoted context omitted.

[flagged]

How would you know unless you check your credit card statement every day?

FWIW, some banks will let you setup email alerts for when your cc is used, or used over a certain threshold.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#195

Earlier quoted context omitted.

You assume that regulation can just make security magically happen. I see no reason to assume that premise to be correct in practice. It's not like the US Government hasn't been breached countless times or had Supreme Court opinions leaked; and it's not like corporations that really tried and should be examples of best practice haven't also been breached. Also, what law can prevent insider attacks? There's already pl…

an executive or two in jail and we'll sure enough see security magically happen.

Should we throw the President in jail if the government gets breached?

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#196
post #65

I was a victim of this last October and November on a T-Mobile number. This is what occurred: - My Gmail account was compromised - My Amazon account was compromised In Gmail, they added a filter to hide any shipping or customer service messages from Amazon. In Amazon, every other day, they placed an order for a ~500 USD GoPro device, delivered to an address in NYC. This address changed with every order. Both password…

[deleted]

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#198
post #8

> T-Mobile declined to answer questions about what it may be doing to beef up employee authentication. But Nicholas Weaver, a researcher and lecturer at University of California, Berkeley’s International Computer Science Institute, said T-Mobile and all the major wireless providers should be requiring employees to use physical security keys for that second factor when logging into company resources. > “These breaches…

Yubikeys and macs are not magic solutions. That's not good security thinking. The same passwordless b.s. that's spreading like cancer is another thing.

Bigcorp networks are emergent, not pieced together. Threat actors just need one or two flaws. Case in point, the mac and yubikey corp with big fat wallet that was hacked: uber.

Everyone is a backseat driver with silverbullet solutions, meanwhile there are decades of research and best practices solve all these problems.

People who chase absolute securitu through one size fits all solutions do more harm than good.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#199

Earlier quoted context omitted.

Scary, this just convinced me to turn off text-based 2FA and only have Google Auth App (+ backup keys). Thank you.

Another different failure point. I once broke my android phone and bought and set up a new one - only to find I can no longer access my Gmail account that I used before with my Google authenticator, so I am locked out forever from that account. I had a backup but was not able to find it. Despite knowing hundreds of contact emails (all backed up in thunderbird), account history, password history, etc - for years I hav…

> I had a backup but was not able to find it.

So you didn't have one lol. I understand that's an extremely frustrating situation though. Part of making backups is testing them once in a while (at least making sure they exist). Something else you could've done previously was to use Authy or Aegis which helps you backup the seeds themselves encrypted under a passphrase so you can recover the accounts even if you lose everything else. Although of course, all of this depends on your threat model, if you don't care about SIM swaps or if losing the account is still much more worrying then I guess it's just a unnecessary hassle/risk.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#200

How does one protect themselves from this? I have an iphone with esim and 2FA on most things, but there are still use cases that send codes via text.

Most of these breaches happen because someone gets targeted - something about their public profile lands them on the radar of the hackers. Then the hackers dig into the profile looking for associated phone numbers. So to mitigate this, you could (1) reduce your public profile, which is out of scope here, and/or (2) minimize phone number exposure. You want to make it impossible for someone targeting you to locate the phone number you use for 2FA on a particular site.

To minimize phone number exposure, you want to send the phone number to as few third parties as you can. You don't want it to show up in any databases, including in breached databases from hacks of companies where you stored your phone number for 2FA purposes. Unfortunately this means the only true solution is a unique phone number per account with SMS 2FA, but that's obviously not practical. So what can you do?

A VOIP number like one from Google Voice is the next best solution for receiving 2FA SMS codes to a dedicated number that you keep separately from your personal phone number. This way you receive texts purely through software and don't expose yourself to SIM swapping at the Mobile ISP level. Unfortunately, some providers won't accept Google Voice or VOIP numbers, so for them you're back to square one... maybe as a backup option (only for those sites), you could use a cheap phone with a pay-as-you-go plan; it's not great, because you're still vulnerable to SIM swapping, but at least you have a dedicated number for SMS 2FA.

Looking at the problem more widely, it would be nice if my phone or mobile ISP could solve this problem for me, with something akin to disposable phone numbers (think Apple Private Relay, or temporary credit card numbers from the bank) or a dedicated 2FA code relaying service (think Authy or Google Authenticator - in fact, maybe they could offer SMS numbers as a feature, although that seems at least as dangerous as the status quo).

Post reply on HN