Earlier quoted context omitted.
Scary, this just convinced me to turn off text-based 2FA and only have Google Auth App (+ backup keys). Thank you.
Another different failure point. I once broke my android phone and bought and set up a new one - only to find I can no longer access my Gmail account that I used before with my Google authenticator, so I am locked out forever from that account. I had a backup but was not able to find it. Despite knowing hundreds of contact emails (all backed up in thunderbird), account history, password history, etc - for years I hav…
Hackers claim they breached T-Mobile more than 100 times in 2022
291–300 of 342 posts
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#292Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#293My approach to this is to use a google voice phone number where all SMS get sent to email. The voice account and the gmail account are the same google account which is secure by hardware 2FA yubikey login. I have a cell phone with an entirely different number that I use for non-2FA things so if it gets compromised i'm OK. I do access that email from that phone, so I suppose i'm a bit vulnerable to targeted phone thef…
This works pretty well until google decides to block your account randomly one day.
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#294I was a victim of this last October and November on a T-Mobile number. This is what occurred: - My Gmail account was compromised - My Amazon account was compromised In Gmail, they added a filter to hide any shipping or customer service messages from Amazon. In Amazon, every other day, they placed an order for a ~500 USD GoPro device, delivered to an address in NYC. This address changed with every order. Both password…
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#295Earlier quoted context omitted.
Yubikeys and macs are not magic solutions. That's not good security thinking. The same passwordless b.s. that's spreading like cancer is another thing. Bigcorp networks are emergent, not pieced together. Threat actors just need one or two flaws. Case in point, the mac and yubikey corp with big fat wallet that was hacked: uber. Everyone is a backseat driver with silverbullet solutions, meanwhile there are decades of r…
While normally I would agree wholeheartedly with this, in this very instance I see meaningless abstraction in service of justifying consumer harm. The phishing TTPs outlined in the article can be mitigated with hardware keys, and the places in the corporate network where they must be part of auth workflows can be identified. There are people whose job this is in corporate networks of all levels of piecemeal quagmires…
You have many many best practices, have a good email protection service/sandbox-detonation, MFA, detection+monitoring after the fact, CAP so threat actors can't just login from any random IP or device, threat hunting, user training,etc... these are all things a good security program should be doing to create the most hostile environment for a threat actor.
People had the same frustrating MFA argument on HN with Uber when it was hacked but long after the news story hype died down it was revealed that the TA got a contractors' creds via infostealer malware. Access to corporate networks is a common trade item in certain forums.
In this case mfa of any kind, cap and url-rewriting email security service are all layers of defense that could have caught this before impact.
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#296It is an open secret that criminal groups also pay unscrupulous T-Mobile employees to assist with SIM-swap attacks. I am not sure at what scale this happens, as those instances _should_ be easy to trace and prosecute. But I have seen evidence of criminals reaching out and offering "side work" on the T-mobile subreddits, as an example. In those cases, hardware keys for employees would not help.
> those instances _should_ be easy to trace and prosecute I suspect that the employees aren't merely doing a sim swap attack with their work login credentials. Like you say, they'd clearly get fired/prosecuted for that. Instead, I suspect criminal X buys a nice thing delivered to employee Y's house. Then, criminal X phones the helpdesk repeatedly till they get connected to employee Y during working hours. Then, they…
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#297Earlier quoted context omitted.
Simjacking. https://en.wikipedia.org/wiki/SIM_swap_scam
Wait. Isn't it painfully obvious when you've been simjacked? If your phone suddenly loses signal and refuses to register with the network, you know something is up. You may think it was a malfunction of your phone or your network, but it's pretty much a definition of a modern-day "drop everything you're doing and deal with it" emergency. You can't not be aware of it, or be unsure if it happened to you.
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#298Earlier quoted context omitted.
As an InfoSec professional, what you describe sounds more like a device-level compromise of your iphone, perhaps through a malicious app, or link you clicked. What your experienced can't be done with just a sim swap attack, as you would have lost access to your phone number. And it can't be done with the described T-Mobile hack, as it would have given the hackers silent access to your texts, so they could have reset…
Read up on credential stuffing, this is increasingly common. With all the recent breaches, there are groups that use old passwords to quickly identify MFA locked accounts behind re-used passwords. These lists are then sold to people who will, one at a time, pay about 10k for a SIM swap on individually targeted users. There are lists floating around with 10s of thousands, or hundreds of thousands of users with known p…
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#299I've been thinking about this a bit more and I think the right path forward is to impose the same fiduciary liabilities and regulations on cellular providers that banks enjoy . Phones are used as authentication devices for bank transactions. If cellular providers have to go through all the same audits of controls as banks and share the same fiduciary liabilities that may raise the bar for phishing attempts. This may…
That may also raise prices massively. I prefer that mobile carriers get dumber (collect less info) and less regulated, not smarter and more regulated.
If your business relies on SMS for authentication, you are liable for all the fallout of using an insecure channel.
It's the bank's job to secure your funds, not a mobile carrier's. Let's keep it that way and make it more clear to consumers and businesses.
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#300Shame on T-Mobile. That said, perhaps everybody using SMS 2FA is equally culpable (e.g. most banks). Nobody who has worked at a mobile carrier would ever think that they're ready to be high-value targets. So it's puzzling that the banks are so eager to put them in that position.
1. Businesses using insecure channels to do authentication and validation.
2. Mobile carriers