Live data from Hacker News

Hackers claim they breached T-Mobile more than 100 times in 2022

krebsonsecurity.com

301–310 of 342 posts

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#301
post #152

Earlier quoted context omitted.

The prohibition against using a VoIP number for banking purposes is stupid. They already have the full battery of KYC info on me: if I want to use a VoIP number for 2FA (because they are so behind the times they don't support FIDO or even TOTP) then unless law says they cannot they need to allow it. And while on the topic of banks, most will suspend access to your online portal if you log in with a VPN. Give me a ban…

Both Fidelity and Schwab allow non-SMS 2FA. They both use Symantec VIP but it’s fairly easy (for developers at least) to export those tokens and import them into something like Authy, Google Authenticator etc. https://ketanvijayvargiya.com/257-symantec-vip-authy/

In the case of Schwab it's only with their app. If I wanted a geolocation leash up my ass I wouldn't be complaining about this: if they don't trust me as a customer then screw them, I'll find a bank who does. Schwab's notion of non-SMS 2FA is their app. I want to use my laptop on a VPN using a FIDO key or TOTP and Schwab doesn't support this.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#302

You know, I’m starting to become slightly more serious about switching carriers solely based on how terrible it would be to experience SMS/Call diverting of my number. While I use a yubikey, OTP (where possible), and unique passwords…there’s still places where I have no choice and my number is my auth (or stupidly a reset option). I genuinely am happy with TMO service in the US, and frankly abroad it’s excellent…but…

I'm on TMO in the US and haven't ditched it yet for the same reasons. I just take all possible precautions. Namely, never use your TMO phone number for any kind of 2FA on other services. Use TTOP, Yubi, and if those aren't available on a particular service then Google Voice for SMS 2FA. If GV isn't allowed, then obfuscate your username, password, and disable account recovery on that service, among other precautions (or just don't use that service at all, find a replacement).

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#303

Earlier quoted context omitted.

SMS as a second factor is almost a security downgrade. Phone companies are terrible, you shouldn't be trusting them with authentication. Plus it means you can't authenticate when your phone is out of coverage. Just a bad solution that shouldn't be used. TOTP is so easy to set up that it makes no sense to use SMS, and the even better hardware keys are only slightly less convenient.

SMS allows you to collect phone numbers which are quite good at identifying users for tracking and ad targeting though. And since most large tech companies are advertising companies (in whole or in part) it is no surprise they chose this as a second factor. Even if you try to avoid using SMS for 2FA they'll try to collect the number for account verification or recovery, with regular nags or lately go straight to exto…

[deleted]

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#304
post #21

Was thinking about moving a line to Google Fi for this reason. I know they just resell T-Mobile bandwidth, but would they provide better account level security? Is it common for Google Fi customers to get SIM swapped?

yup https://www.bleepingcomputer.com/news/security/google-fi-dat... my friend had google fi and was caught in this, among other things they had their instagram taken over. scary few days. thankfully their roommate works at meta... I think the only way to be really safe is to use one of the smaller MVNOs and never ever ever reveal who your carrier is

Do you know any MVNO that does security really well?

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#305

Earlier quoted context omitted.

SMS in unencrypted, and Google SE has been compromised for much if not all of 2022. From what I can tell the issue persists. I officially reported it in December, and again in January, and again in February. Pretty wild, TBH. Think about the number of services that have Google SE and Ads integration. Makes me nauseous. Did you happen to report to Apple and Google (for documentation)?

In what way is the google search engine compromised?

Ways which I shared with Google, because it's a very serious privacy and security vulnerability.

We need more robust security integration to catch things before they are pushed to results. I understand latency will increase, and some ads revenue will decrease. But like, isn't it also cool to have a customer base that is better protected against egregious attacks, attacks that could be prevented? IMO, yes. It's called "stewardship."

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#306
post #62

Earlier quoted context omitted.

I've always figured I should have two numbers—one I let people know, and one for 2fa. But that's ~$20/mo and a moderate annoyance, so for now mostly just fingers crossed that eventually everywhere that matters will allow me to switch fully to authentication apps and hardware keys.

if you have an apple watch, depending on your plan, it may have a different phone number wonder if that works...

Can also do that with iPads. I have an iPhone and iPad both on the same T-mobile account but with different numbers.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#307
post #118

Earlier quoted context omitted.

https://www.bleepingcomputer.com/news/security/google-fi-dat... This article says that Google Fi customers were SIM swapped due to a T-Mobile breach. Even though "[t]here was no access to Google's systems or any systems overseen by Google."

> These attacks are conducted using social engineering, where the threat actor impersonates the customer and requests that the number be ported to a new device for some reason. To convince the mobile carrier that they are the customer, they provide personal information exposed to phishing attacks and data breaches. > As the Google Fi data breach includes phone numbers, which can easily be linked to a customer's name,…

Does Google Fi have real humans for customer support? Last I checked they didn't, but it's been a while.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#309

This follows on the unpopular news story that T-Mobile will be requiring you to give them your debit card or bank account information to continue to qualify for their Autopay discount. https://www.cnet.com/tech/mobile/t-mobile-is-dropping-its-au...

How would you do autopay without giving them either a credit card or bank wire info? Seems at least one of those is required.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#310
post #197

This was at least couple of decades ago but I remember how they would send your password to your phone over SMS.

Yup, just over one decade ago actually:

https://plaintextoffenders.com/post/4567498592/t-mobilenet

And more recently in 2018:

https://plaintextoffenders.com/post/174100751368/meint-mobil...

A few more in the master list here:

https://github.com/plaintextoffenders/plaintextoffenders/blo...

Post reply on HN