Live data from Hacker News

Hackers claim they breached T-Mobile more than 100 times in 2022

krebsonsecurity.com

291–300 of 342 posts

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#291

Earlier quoted context omitted.

Scary, this just convinced me to turn off text-based 2FA and only have Google Auth App (+ backup keys). Thank you.

Another different failure point. I once broke my android phone and bought and set up a new one - only to find I can no longer access my Gmail account that I used before with my Google authenticator, so I am locked out forever from that account. I had a backup but was not able to find it. Despite knowing hundreds of contact emails (all backed up in thunderbird), account history, password history, etc - for years I hav…

With Authy I can enter a backup password and download everything to a new phone. I suppose that's a different failure point but still possibly worth the trade-off? Yubikey is the next level up.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#293

My approach to this is to use a google voice phone number where all SMS get sent to email. The voice account and the gmail account are the same google account which is secure by hardware 2FA yubikey login. I have a cell phone with an entirely different number that I use for non-2FA things so if it gets compromised i'm OK. I do access that email from that phone, so I suppose i'm a bit vulnerable to targeted phone thef…

This works pretty well until google decides to block your account randomly one day.

My Google Voice keeps randomly losing its phone number. I haven't bothered figuring out why, maybe inactivity, but it doesn't matter cause I've already crossed it off as something to rely on.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#294
post #65

I was a victim of this last October and November on a T-Mobile number. This is what occurred: - My Gmail account was compromised - My Amazon account was compromised In Gmail, they added a filter to hide any shipping or customer service messages from Amazon. In Amazon, every other day, they placed an order for a ~500 USD GoPro device, delivered to an address in NYC. This address changed with every order. Both password…

This is why you don’t use sms as 2FA. And use iOS. We’re you using android?

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#295
post #198

Earlier quoted context omitted.

Yubikeys and macs are not magic solutions. That's not good security thinking. The same passwordless b.s. that's spreading like cancer is another thing. Bigcorp networks are emergent, not pieced together. Threat actors just need one or two flaws. Case in point, the mac and yubikey corp with big fat wallet that was hacked: uber. Everyone is a backseat driver with silverbullet solutions, meanwhile there are decades of r…

While normally I would agree wholeheartedly with this, in this very instance I see meaningless abstraction in service of justifying consumer harm. The phishing TTPs outlined in the article can be mitigated with hardware keys, and the places in the corporate network where they must be part of auth workflows can be identified. There are people whose job this is in corporate networks of all levels of piecemeal quagmires…

I don't disagree that yubikeys are effective but even sms 2fa could have been effective! This is missing the forest for the trees. Even then, what if it wasn't credential harvesting but a download for an infostealer? Then even yubikeys are ineffective due to cookie theft.

You have many many best practices, have a good email protection service/sandbox-detonation, MFA, detection+monitoring after the fact, CAP so threat actors can't just login from any random IP or device, threat hunting, user training,etc... these are all things a good security program should be doing to create the most hostile environment for a threat actor.

People had the same frustrating MFA argument on HN with Uber when it was hacked but long after the news story hype died down it was revealed that the TA got a contractors' creds via infostealer malware. Access to corporate networks is a common trade item in certain forums.

In this case mfa of any kind, cap and url-rewriting email security service are all layers of defense that could have caught this before impact.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#296

It is an open secret that criminal groups also pay unscrupulous T-Mobile employees to assist with SIM-swap attacks. I am not sure at what scale this happens, as those instances _should_ be easy to trace and prosecute. But I have seen evidence of criminals reaching out and offering "side work" on the T-mobile subreddits, as an example. In those cases, hardware keys for employees would not help.

> those instances _should_ be easy to trace and prosecute I suspect that the employees aren't merely doing a sim swap attack with their work login credentials. Like you say, they'd clearly get fired/prosecuted for that. Instead, I suspect criminal X buys a nice thing delivered to employee Y's house. Then, criminal X phones the helpdesk repeatedly till they get connected to employee Y during working hours. Then, they…

Why do you need a gift to the employee?

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#297

Earlier quoted context omitted.

Simjacking. https://en.wikipedia.org/wiki/SIM_swap_scam

Wait. Isn't it painfully obvious when you've been simjacked? If your phone suddenly loses signal and refuses to register with the network, you know something is up. You may think it was a malfunction of your phone or your network, but it's pretty much a definition of a modern-day "drop everything you're doing and deal with it" emergency. You can't not be aware of it, or be unsure if it happened to you.

You very much can not be aware of it. Consider what happens when you're simswapped at 2 am. Are you going to notice that? Probably not. And maybe not after you get up and check your phone. Because your phone may be connected to the internet via your home wifi and you don't even notice your phone has no bars and no service because you're still able to browse the web and check email.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#298
post #270
post #242

Earlier quoted context omitted.

As an InfoSec professional, what you describe sounds more like a device-level compromise of your iphone, perhaps through a malicious app, or link you clicked. What your experienced can't be done with just a sim swap attack, as you would have lost access to your phone number. And it can't be done with the described T-Mobile hack, as it would have given the hackers silent access to your texts, so they could have reset…

Read up on credential stuffing, this is increasingly common. With all the recent breaches, there are groups that use old passwords to quickly identify MFA locked accounts behind re-used passwords. These lists are then sold to people who will, one at a time, pay about 10k for a SIM swap on individually targeted users. There are lists floating around with 10s of thousands, or hundreds of thousands of users with known p…

The parent comment has a point though - after SIM swap attack, all SMS messages would stop arriving at the victim device - unless the attackers swap it back again after every 2FA code. If they had access to a dashboard at t-mobile this might be possible but it sounds like a lot of effort to steal a few thousand dollars.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#299

I've been thinking about this a bit more and I think the right path forward is to impose the same fiduciary liabilities and regulations on cellular providers that banks enjoy . Phones are used as authentication devices for bank transactions. If cellular providers have to go through all the same audits of controls as banks and share the same fiduciary liabilities that may raise the bar for phishing attempts. This may…

>Phones are used as authentication devices for bank transactions. If cellular providers have to go through all the same audits of controls as banks and share the same fiduciary liabilities that may raise the bar for phishing attempts.

That may also raise prices massively. I prefer that mobile carriers get dumber (collect less info) and less regulated, not smarter and more regulated.

If your business relies on SMS for authentication, you are liable for all the fallout of using an insecure channel.

It's the bank's job to secure your funds, not a mobile carrier's. Let's keep it that way and make it more clear to consumers and businesses.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#300

Shame on T-Mobile. That said, perhaps everybody using SMS 2FA is equally culpable (e.g. most banks). Nobody who has worked at a mobile carrier would ever think that they're ready to be high-value targets. So it's puzzling that the banks are so eager to put them in that position.

The order of shaming should be:

1. Businesses using insecure channels to do authentication and validation.

2. Mobile carriers

Post reply on HN