Earlier quoted context omitted.
Lack of knowledge of vulnerability is not the limiting factor in this case. All a "free for all" would do in this case is make more noise in which malicious actors can hide in the logs.
Are you saying they're aware of all these vulnerabilities? Why don't they fix them? Can one of the wealthiest companies in the nation not fix vulnerabilities they're already aware of? What is the limiting factor here? Competence? My conspiracy theory is that my idea will never be implemented because it would expose the "job creator" class to an objective measure of their competence, and they would not fare well. Head…
Hackers claim they breached T-Mobile more than 100 times in 2022
211–220 of 342 posts
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#212Earlier quoted context omitted.
I use Google voice for everything... except my bank because they said using T-Mobile is so much more safer than Google so I had to switch back
The prohibition against using a VoIP number for banking purposes is stupid. They already have the full battery of KYC info on me: if I want to use a VoIP number for 2FA (because they are so behind the times they don't support FIDO or even TOTP) then unless law says they cannot they need to allow it. And while on the topic of banks, most will suspend access to your online portal if you log in with a VPN. Give me a ban…
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#213> T-Mobile declined to answer questions about what it may be doing to beef up employee authentication. But Nicholas Weaver, a researcher and lecturer at University of California, Berkeley’s International Computer Science Institute, said T-Mobile and all the major wireless providers should be requiring employees to use physical security keys for that second factor when logging into company resources. > “These breaches…
I think why regulation hasn’t happened is because the computer industry has changed so quickly. Two-factor auth wasn’t even a commonly accepted best practice two decades ago. And regulation takes a while to create and put into practice and with the rate things are going, by the time regulation has been out in place, the current best practices will have changed. Whereas writing regulation on building bridges is easy b…
It also doesn't help that the US government is a barely-functioning kleptocracy. They're more concerned with passing legislation about transgender boogymen while they line their pockets than they are about ... well, anything else.
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#214Earlier quoted context omitted.
It's subtle with the UI but you can choose not to allow SMS by removing your phone number from Google after setting up alternative 2FA. If they don't have a number they can't sim-jack
This is one of the most important pieces of security advice that is often overlooked: remove your phone number from EVERYTHING. You can also enable Advanced Protection[1] for your Google account, but other repeat offenders like Github will continue to allow SMS fallback to bypass 2FA if you have a phone number listed anywhere. 1. https://landing.google.com/advancedprotection/
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#215> T-Mobile declined to answer questions about what it may be doing to beef up employee authentication. But Nicholas Weaver, a researcher and lecturer at University of California, Berkeley’s International Computer Science Institute, said T-Mobile and all the major wireless providers should be requiring employees to use physical security keys for that second factor when logging into company resources. > “These breaches…
After an incident our compliance people told us we cannot have different 2FA options for the same user, so yes in fact if you need to use a legacy system ever then you cannot have a yubikey enabled anywhere.
imo you should always have at least two 2fa hids in case one gets damaged or lost or whatever and you need to force log yourself out or something.
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#216My approach to this is to use a google voice phone number where all SMS get sent to email. The voice account and the gmail account are the same google account which is secure by hardware 2FA yubikey login. I have a cell phone with an entirely different number that I use for non-2FA things so if it gets compromised i'm OK. I do access that email from that phone, so I suppose i'm a bit vulnerable to targeted phone thef…
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#217> T-Mobile declined to answer questions about what it may be doing to beef up employee authentication. But Nicholas Weaver, a researcher and lecturer at University of California, Berkeley’s International Computer Science Institute, said T-Mobile and all the major wireless providers should be requiring employees to use physical security keys for that second factor when logging into company resources. > “These breaches…
After an incident our compliance people told us we cannot have different 2FA options for the same user, so yes in fact if you need to use a legacy system ever then you cannot have a yubikey enabled anywhere.
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#218Earlier quoted context omitted.
> In Gmail, they added a filter to hide any shipping or customer service messages from Amazon. I gotta admit, that's pretty clever. Crude, but effective.
I was about to comment the same thing. It's very simple but I don't think I would have thought of it
Our group is small enough that I get very few alerts at all, and I've caught two compromises that way.
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#219Earlier quoted context omitted.
The prohibition against using a VoIP number for banking purposes is stupid. They already have the full battery of KYC info on me: if I want to use a VoIP number for 2FA (because they are so behind the times they don't support FIDO or even TOTP) then unless law says they cannot they need to allow it. And while on the topic of banks, most will suspend access to your online portal if you log in with a VPN. Give me a ban…
Both Fidelity and Schwab allow non-SMS 2FA. They both use Symantec VIP but it’s fairly easy (for developers at least) to export those tokens and import them into something like Authy, Google Authenticator etc. https://ketanvijayvargiya.com/257-symantec-vip-authy/
I know that Vanguard, for instance, supports non-SMS 2FA but doesn't let you disable SMS as a fallback (and I'd rather not just totally remove all phone numbers, but maybe I have to...).
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#220Earlier quoted context omitted.
That’s assuming you regulate a very specific thing versus the end goal. To me the appropriate regulation is to find a way to cause real harm to T-Mobile when they are breached. When repeated like this or if done through effectively negligence, then they shouldn’t be allowed to be in business anymore. We gotta stop the tiny fines.. jail, billions of dollars in fines, remove their business license… something large need…
One way to do so would be to make it so wireless companies can lose access to spectrum as a consequence of customer data breaches. Let someone else who can keep customer data secure have it instead.
I think financial penalties are still the best bet if they are large enough to really hit profitability but not large enough to kill the company.