Don't use a mere mobile number for the backup access to anything inportant!
Hackers claim they breached T-Mobile more than 100 times in 2022
201–210 of 342 posts
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#202I see people jumping towards regulation, but that has the side-effect of making it even more difficult for there to be any competition against these monopolies. What we really need is legitimate competition, to enable consumers to vote with their wallet and move to a competitor that takes the security of their customer's private data seriously.
If your snappy upstart cellular network can't afford to give out Yubikeys to employees, I don't want you interconnecting with the rest of the phone system.
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#203Earlier quoted context omitted.
I can use my phone number for 2FA and/or as a recovery phone number. Would you advise to remove it from both places or just from 2FA?
Remove it from both. However make sure that you have quite a lot of backups of your 2FA backup keys, and maybe even one offline backup of your seed, if you lose them, the account is gone (which is a good thing, I guess).
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#204Which cell phone network would you guys recommend for people who care about security?
Although, "bills" reminds me - a lot of companies overload the use of 2FA SMS for both identification and 2FA purposes, not to mention most customer service centers expect the call to originate from the same number that receives 2FA SMS messages for authenticating to the account being serviced.
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#205> T-Mobile declined to answer questions about what it may be doing to beef up employee authentication. But Nicholas Weaver, a researcher and lecturer at University of California, Berkeley’s International Computer Science Institute, said T-Mobile and all the major wireless providers should be requiring employees to use physical security keys for that second factor when logging into company resources. > “These breaches…
Yubikeys and macs are not magic solutions. That's not good security thinking. The same passwordless b.s. that's spreading like cancer is another thing. Bigcorp networks are emergent, not pieced together. Threat actors just need one or two flaws. Case in point, the mac and yubikey corp with big fat wallet that was hacked: uber. Everyone is a backseat driver with silverbullet solutions, meanwhile there are decades of r…
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#206I see people jumping towards regulation, but that has the side-effect of making it even more difficult for there to be any competition against these monopolies. What we really need is legitimate competition, to enable consumers to vote with their wallet and move to a competitor that takes the security of their customer's private data seriously.
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#207Earlier quoted context omitted.
I use Google voice for everything... except my bank because they said using T-Mobile is so much more safer than Google so I had to switch back
The prohibition against using a VoIP number for banking purposes is stupid. They already have the full battery of KYC info on me: if I want to use a VoIP number for 2FA (because they are so behind the times they don't support FIDO or even TOTP) then unless law says they cannot they need to allow it. And while on the topic of banks, most will suspend access to your online portal if you log in with a VPN. Give me a ban…
They both use Symantec VIP but it’s fairly easy (for developers at least) to export those tokens and import them into something like Authy, Google Authenticator etc.
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#208I've been thinking about this a bit more and I think the right path forward is to impose the same fiduciary liabilities and regulations on cellular providers that banks enjoy . Phones are used as authentication devices for bank transactions. If cellular providers have to go through all the same audits of controls as banks and share the same fiduciary liabilities that may raise the bar for phishing attempts. This may…
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#209I see people jumping towards regulation, but that has the side-effect of making it even more difficult for there to be any competition against these monopolies. What we really need is legitimate competition, to enable consumers to vote with their wallet and move to a competitor that takes the security of their customer's private data seriously.
> making it even more difficult for there to be any competition against these monopolies If your snappy upstart cellular network can't afford to give out Yubikeys to employees, I don't want you interconnecting with the rest of the phone system.
I planned and did the roll out of Yubikeys at the last place I worked, before there was a dollar in sales, and the lifecycle could be supported with 2 people (minutes at most out of each day for support) and an integration to our HR platform that automated procurement and mailing of keys.
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#210> T-Mobile declined to answer questions about what it may be doing to beef up employee authentication. But Nicholas Weaver, a researcher and lecturer at University of California, Berkeley’s International Computer Science Institute, said T-Mobile and all the major wireless providers should be requiring employees to use physical security keys for that second factor when logging into company resources. > “These breaches…