Earlier quoted context omitted.
I think why regulation hasn’t happened is because the computer industry has changed so quickly. Two-factor auth wasn’t even a commonly accepted best practice two decades ago. And regulation takes a while to create and put into practice and with the rate things are going, by the time regulation has been out in place, the current best practices will have changed. Whereas writing regulation on building bridges is easy b…
> I think why regulation hasn’t happened is because the computer industry has changed so quickly. It also doesn't help that the US government is a barely-functioning kleptocracy. They're more concerned with passing legislation about transgender boogymen while they line their pockets than they are about ... well, anything else.
Hackers claim they breached T-Mobile more than 100 times in 2022
221–230 of 342 posts
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#222Earlier quoted context omitted.
I think why regulation hasn’t happened is because the computer industry has changed so quickly. Two-factor auth wasn’t even a commonly accepted best practice two decades ago. And regulation takes a while to create and put into practice and with the rate things are going, by the time regulation has been out in place, the current best practices will have changed. Whereas writing regulation on building bridges is easy b…
I agree completely. I didn't ask why government enforced regulation hasn't happened. I asked why industry self-regulation has failed. I've worked in a regulatory/security role for a major conglomerate before. I'm not saying I expected self-regulation to work. But, if you are in a position of customers seeing direct harm every day , it's not unreasonable to ask why there is a failure here.
Self-regulation has failed because the cost of a data breach remains relatively low compared to implementing security measures, at least on the surface.
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#223Earlier quoted context omitted.
That’s assuming you regulate a very specific thing versus the end goal. To me the appropriate regulation is to find a way to cause real harm to T-Mobile when they are breached. When repeated like this or if done through effectively negligence, then they shouldn’t be allowed to be in business anymore. We gotta stop the tiny fines.. jail, billions of dollars in fines, remove their business license… something large need…
One way to do so would be to make it so wireless companies can lose access to spectrum as a consequence of customer data breaches. Let someone else who can keep customer data secure have it instead.
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#224Earlier quoted context omitted.
Both Fidelity and Schwab allow non-SMS 2FA. They both use Symantec VIP but it’s fairly easy (for developers at least) to export those tokens and import them into something like Authy, Google Authenticator etc. https://ketanvijayvargiya.com/257-symantec-vip-authy/
Do you happen to know if they allow you to also totally disable SMS 2FA? I know that Vanguard, for instance, supports non-SMS 2FA but doesn't let you disable SMS as a fallback (and I'd rather not just totally remove all phone numbers, but maybe I have to...).
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#225Earlier quoted context omitted.
I have no idea what you are talking about here. SIM swap and spam texts/calls are entirely different issues.
If it's scalable to mass call a good chunk of the US population, I'm sure it's scalable to mass call providers to socially engineer a SIM swap.
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#226Earlier quoted context omitted.
I think why regulation hasn’t happened is because the computer industry has changed so quickly. Two-factor auth wasn’t even a commonly accepted best practice two decades ago. And regulation takes a while to create and put into practice and with the rate things are going, by the time regulation has been out in place, the current best practices will have changed. Whereas writing regulation on building bridges is easy b…
Aviation industry can introduce new regulation fast. One example would be reinforced cockpit doors. Prompted by events in September 2001, new standards published four months later (January 2002), expected to be completed fifteen months after that (April 2003). https://avalon.law.yale.edu/sept11/faa_001.asp
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#227Earlier quoted context omitted.
I think why regulation hasn’t happened is because the computer industry has changed so quickly. Two-factor auth wasn’t even a commonly accepted best practice two decades ago. And regulation takes a while to create and put into practice and with the rate things are going, by the time regulation has been out in place, the current best practices will have changed. Whereas writing regulation on building bridges is easy b…
> Two-factor auth wasn't even a commonly accepted best practice two decades ago. Maybe, had you said three decades? But not two. It was already mature by then. Two decades ago was 2003. Even consumer banking was online, and in many countries exclusively 2FA. I've worked the banking space then and we absolutely had smart cards. Military and defense had them everywhere. Proprietary solutions had already gone away repla…
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#228Earlier quoted context omitted.
why do you think that? Presumably Google Voice uses a phone company downstream, which means if that company is hacked they can reassign your number to someone else and thus you have the classic SIM jacking attack.
Which phone company does the hacker call to trick into believing they are Google?
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#229Earlier quoted context omitted.
You assume that regulation can just make security magically happen. I see no reason to assume that premise to be correct in practice. It's not like the US Government hasn't been breached countless times or had Supreme Court opinions leaked; and it's not like corporations that really tried and should be examples of best practice haven't also been breached. Also, what law can prevent insider attacks? There's already pl…
> There's no law that just "makes security happen" In another thread I proposed making white-hat hacking legally protected, even without permission from the company. If your system is constantly being tested by mostly white-hat hackers seeking their next responsible disclosure and bounty, then that's something. Bug bounties already exist, but they're opt-in, and companies that need them the most are not opting-in. We…
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#230I worked for TMobile for 4 days in 2021. I don't usually apply to big companies but money was tight because pandemic and I needed a job quick. I was assigned to work on the config server (think in-house developed consul or etcd) and it was awful. "If this specific config value is being set by Service A then what is actually written should be twice the given value, but if Service B is reading the value, return 1/3 of…
So T-Mobile offered you a "quick job" that immediately gave you access to their inner sanctum?
These threads are a hoot.