Live data from Hacker News

Hackers claim they breached T-Mobile more than 100 times in 2022

krebsonsecurity.com

211–220 of 342 posts

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#211

Earlier quoted context omitted.

Lack of knowledge of vulnerability is not the limiting factor in this case. All a "free for all" would do in this case is make more noise in which malicious actors can hide in the logs.

Are you saying they're aware of all these vulnerabilities? Why don't they fix them? Can one of the wealthiest companies in the nation not fix vulnerabilities they're already aware of? What is the limiting factor here? Competence? My conspiracy theory is that my idea will never be implemented because it would expose the "job creator" class to an objective measure of their competence, and they would not fare well. Head…

You can read lots of comments in these threads about the cost/benefit analysis of mitigating the vulnerabilities. And whenever that cost/benefit calculation gets very complex, the default is to not get too worked up about fixing the status quo because "it's complicated."

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#212
post #152
post #73

Earlier quoted context omitted.

I use Google voice for everything... except my bank because they said using T-Mobile is so much more safer than Google so I had to switch back

The prohibition against using a VoIP number for banking purposes is stupid. They already have the full battery of KYC info on me: if I want to use a VoIP number for 2FA (because they are so behind the times they don't support FIDO or even TOTP) then unless law says they cannot they need to allow it. And while on the topic of banks, most will suspend access to your online portal if you log in with a VPN. Give me a ban…

Chase won't let you use voip for 2fa. Ameritrade works.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#213
post #84
post #8

> T-Mobile declined to answer questions about what it may be doing to beef up employee authentication. But Nicholas Weaver, a researcher and lecturer at University of California, Berkeley’s International Computer Science Institute, said T-Mobile and all the major wireless providers should be requiring employees to use physical security keys for that second factor when logging into company resources. > “These breaches…

I think why regulation hasn’t happened is because the computer industry has changed so quickly. Two-factor auth wasn’t even a commonly accepted best practice two decades ago. And regulation takes a while to create and put into practice and with the rate things are going, by the time regulation has been out in place, the current best practices will have changed. Whereas writing regulation on building bridges is easy b…

> I think why regulation hasn’t happened is because the computer industry has changed so quickly.

It also doesn't help that the US government is a barely-functioning kleptocracy. They're more concerned with passing legislation about transgender boogymen while they line their pockets than they are about ... well, anything else.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#214
post #192
post #184

Earlier quoted context omitted.

It's subtle with the UI but you can choose not to allow SMS by removing your phone number from Google after setting up alternative 2FA. If they don't have a number they can't sim-jack

This is one of the most important pieces of security advice that is often overlooked: remove your phone number from EVERYTHING. You can also enable Advanced Protection[1] for your Google account, but other repeat offenders like Github will continue to allow SMS fallback to bypass 2FA if you have a phone number listed anywhere. 1. https://landing.google.com/advancedprotection/

Big benefit of Advanced Protection: you can go tell less technical users to set it up and it will enforce all these best practices (no SMS, two keys, no giving random apps access to GMail...).

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#215
post #8

> T-Mobile declined to answer questions about what it may be doing to beef up employee authentication. But Nicholas Weaver, a researcher and lecturer at University of California, Berkeley’s International Computer Science Institute, said T-Mobile and all the major wireless providers should be requiring employees to use physical security keys for that second factor when logging into company resources. > “These breaches…

After an incident our compliance people told us we cannot have different 2FA options for the same user, so yes in fact if you need to use a legacy system ever then you cannot have a yubikey enabled anywhere.

wow. Hot take but i think yiur compliance team might suck.

imo you should always have at least two 2fa hids in case one gets damaged or lost or whatever and you need to force log yourself out or something.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#216

My approach to this is to use a google voice phone number where all SMS get sent to email. The voice account and the gmail account are the same google account which is secure by hardware 2FA yubikey login. I have a cell phone with an entirely different number that I use for non-2FA things so if it gets compromised i'm OK. I do access that email from that phone, so I suppose i'm a bit vulnerable to targeted phone thef…

This works pretty well until google decides to block your account randomly one day.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#217
post #8

> T-Mobile declined to answer questions about what it may be doing to beef up employee authentication. But Nicholas Weaver, a researcher and lecturer at University of California, Berkeley’s International Computer Science Institute, said T-Mobile and all the major wireless providers should be requiring employees to use physical security keys for that second factor when logging into company resources. > “These breaches…

After an incident our compliance people told us we cannot have different 2FA options for the same user, so yes in fact if you need to use a legacy system ever then you cannot have a yubikey enabled anywhere.

Sounds like you need new compliance people!

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#218

Earlier quoted context omitted.

> In Gmail, they added a filter to hide any shipping or customer service messages from Amazon. I gotta admit, that's pretty clever. Crude, but effective.

I was about to comment the same thing. It's very simple but I don't think I would have thought of it

It's quite common, in fact my "go-to" hacked account rule in Office 365 is "alert me, system admin, anytime anyone creates an outlook/exchange rule".

Our group is small enough that I get very few alerts at all, and I've caught two compromises that way.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#219
post #152

Earlier quoted context omitted.

The prohibition against using a VoIP number for banking purposes is stupid. They already have the full battery of KYC info on me: if I want to use a VoIP number for 2FA (because they are so behind the times they don't support FIDO or even TOTP) then unless law says they cannot they need to allow it. And while on the topic of banks, most will suspend access to your online portal if you log in with a VPN. Give me a ban…

Both Fidelity and Schwab allow non-SMS 2FA. They both use Symantec VIP but it’s fairly easy (for developers at least) to export those tokens and import them into something like Authy, Google Authenticator etc. https://ketanvijayvargiya.com/257-symantec-vip-authy/

Do you happen to know if they allow you to also totally disable SMS 2FA?

I know that Vanguard, for instance, supports non-SMS 2FA but doesn't let you disable SMS as a fallback (and I'd rather not just totally remove all phone numbers, but maybe I have to...).

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#220

Earlier quoted context omitted.

That’s assuming you regulate a very specific thing versus the end goal. To me the appropriate regulation is to find a way to cause real harm to T-Mobile when they are breached. When repeated like this or if done through effectively negligence, then they shouldn’t be allowed to be in business anymore. We gotta stop the tiny fines.. jail, billions of dollars in fines, remove their business license… something large need…

One way to do so would be to make it so wireless companies can lose access to spectrum as a consequence of customer data breaches. Let someone else who can keep customer data secure have it instead.

Most countries only have three large mobile carriers. You can't take action against their actual operations because you would be running out of alternatives pretty soon plus you would cause huge disruption to customers.

I think financial penalties are still the best bet if they are large enough to really hit profitability but not large enough to kill the company.

Post reply on HN