Live data from Hacker News

Hackers claim they breached T-Mobile more than 100 times in 2022

krebsonsecurity.com

231–240 of 342 posts

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#231

Earlier quoted context omitted.

an executive or two in jail and we'll sure enough see security magically happen.

Should we throw the President in jail if the government gets breached?

no, of course not. (nice straw-man attempt, btw)

Just the way boards of companies have fiduciary duty, there should be some of sort customer information protection duty that companies are responsible / liable for. basic security practices are being neglected at far too many companies.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#232

Earlier quoted context omitted.

Are you saying they're aware of all these vulnerabilities? Why don't they fix them? Can one of the wealthiest companies in the nation not fix vulnerabilities they're already aware of? What is the limiting factor here? Competence? My conspiracy theory is that my idea will never be implemented because it would expose the "job creator" class to an objective measure of their competence, and they would not fare well. Head…

You can read lots of comments in these threads about the cost/benefit analysis of mitigating the vulnerabilities. And whenever that cost/benefit calculation gets very complex, the default is to not get too worked up about fixing the status quo because "it's complicated."

Yeah, the cost would be corporate profits, and the benefit would be privacy for average people. Given those tradeoffs, I'm not surprised that those benefiting from corporate profits say "it's complicated", and then choose the course that results in more profits for them (while harming the general public and national security). I'm not surprised, but not happy about it either. But this is turning into more of a political rant so I'll end here.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#233

Earlier quoted context omitted.

Do we know if Google Voice also uses T-Mobile? If not, might be worthwhile to switch SMS 2FA to the Voice number if a service allows voip numbers.

Google Voice isn't a wireless carrier. VoIP only.

This is part of my question. How does Google provision VoIP numbers? When someone calls / texts a VoIP number from a normal number, that call / SMS travels over normal wireless infrastructure. So VoIP numbers are still connected to the same infra, right?

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#234
post #152

Earlier quoted context omitted.

The prohibition against using a VoIP number for banking purposes is stupid. They already have the full battery of KYC info on me: if I want to use a VoIP number for 2FA (because they are so behind the times they don't support FIDO or even TOTP) then unless law says they cannot they need to allow it. And while on the topic of banks, most will suspend access to your online portal if you log in with a VPN. Give me a ban…

Both Fidelity and Schwab allow non-SMS 2FA. They both use Symantec VIP but it’s fairly easy (for developers at least) to export those tokens and import them into something like Authy, Google Authenticator etc. https://ketanvijayvargiya.com/257-symantec-vip-authy/

My bank used to allow email 2fa or SMS, but they recently dropped support for email. I don’t love using email for 2fa but since my email is itself protected with non-SMS 2fa I thought it was the best of the two bad options. Now I’m sad. Ideally my bank would support the FIDO standard and I would use a compatible hardware token.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#235
post #165

Earlier quoted context omitted.

On darknet diaries the stories told are a little more straightforward. They just walk in to the store, steal a tablet out of the manager's hands, run away with it, and make all the changes they can with the logged-in session until corporate locks out the device.

People sell this as a service and supposedly have numbers on how long from a provider tablet is stolen until the device gets locked out. If I remember correctly T-mobile was/is considered to have the "longest" time from when the device is stolen, there for the most valuable.

[deleted]

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#236

I worked for TMobile for 4 days in 2021. I don't usually apply to big companies but money was tight because pandemic and I needed a job quick. I was assigned to work on the config server (think in-house developed consul or etcd) and it was awful. "If this specific config value is being set by Service A then what is actually written should be twice the given value, but if Service B is reading the value, return 1/3 of…

>config server (think in-house developed consul or etcd) and it was awful. "If this specific config value is being set by Service A then what is actually written should be twice the given value, but if Service B is reading the value, return 1/3 of the value as an HTTP form body instead of JSON."

People say dev salaries are way too high but this is basically what internal systems look like at all the places that refuse to pay fair market value.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#237

Earlier quoted context omitted.

Which phone company does the hacker call to trick into believing they are Google?

they pay-off / trick a T-Mobile employee into re-assigning your Google Voice number to them. It's happened before with Google Fi, but I haven't seen any public information about this happening with Google Voice (yet)

> they pay-off / trick a T-Mobile employee into re-assigning your Google Voice number to them.

Are you saying the Google Voice phone number lock is useless and that any carrier can just steal Google Voice numbers regardless of the lock status?

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#238

Earlier quoted context omitted.

> There's no law that just "makes security happen" In another thread I proposed making white-hat hacking legally protected, even without permission from the company. If your system is constantly being tested by mostly white-hat hackers seeking their next responsible disclosure and bounty, then that's something. Bug bounties already exist, but they're opt-in, and companies that need them the most are not opting-in. We…

Legalizing hacking seems like a large loophole that will backfire. Where is the line between white-hat and black-hat?

Did you download 10 gigabytes of personal data and sell it? Or did you responsibly report the vulnerability once it was apparent? There would have to be some guidelines and some attacks like DDoS might still be illegal, etc.

Certainly a risk of this proposal is that some black-hats would get away, but that is already happening, so it's not really a problem of this proposal. This law wont affect black-hats because they already operate outside the law.

The problem is nobody can investigate the security of a company without facing major legal risks. As I linked above, a researcher pressed F12 and next thing he knew the Governor was threatening to prosecute him, and that's just one example. I believe it is a felony if I want to investigate for myself how secure T-Mobile's systems are, because they have not explicitly invited me to do so.

About 10 years ago I was doing some web scraping and came across a website that was exposing PPI (SSNs and more) of thousands of people. It was in an API JSON response, the JavaScript only displayed part of the data though. I just closed the site and never touched it again. I'm not a security researcher, I don't know how to safely report what I saw. It all seems personally risky for little personal gain. So I closed the site and let it go. My attitude has long been that if society wants to offer me some strong legal protections then I'll do the right thing, otherwise, society can burn. Half the nation's personal data can get stolen twice a month, as is already the case. When society cares enough to do something about it maybe I'll change my attitude.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#239

Earlier quoted context omitted.

How is SMS a security risk? As far as I know, SMS is closely tied to a person's identity, especially 'know your customer' regulations. I'm curious how it's a security risk; as far as I know they have to be unique, which is good

Simjacking. https://en.wikipedia.org/wiki/SIM_swap_scam

Wait. Isn't it painfully obvious when you've been simjacked? If your phone suddenly loses signal and refuses to register with the network, you know something is up. You may think it was a malfunction of your phone or your network, but it's pretty much a definition of a modern-day "drop everything you're doing and deal with it" emergency. You can't not be aware of it, or be unsure if it happened to you.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#240

Earlier quoted context omitted.

SMS 2FA is a security risk! I used to work tech support for cell phone providers, and while we were trained about fraud, the nature of the industry low wages, high turnover, makes this a security flaw that financial institutions should not risk.

How is SMS a security risk? As far as I know, SMS is closely tied to a person's identity, especially 'know your customer' regulations. I'm curious how it's a security risk; as far as I know they have to be unique, which is good

Anyone can walk into a T-Mobile store with a fake driving license with your name on it and claim they need help moving their phone number to their new phone. This is of course your number. They will then receive all of your SMS messages.

Or, you know, they can just bribe the store employees. Has happened before, still happens, will keep happening as long as a phone number is considered important for anything at all.

Post reply on HN