Live data from Hacker News

Hackers claim they breached T-Mobile more than 100 times in 2022

krebsonsecurity.com

311–320 of 342 posts

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#311

Shame on T-Mobile. That said, perhaps everybody using SMS 2FA is equally culpable (e.g. most banks). Nobody who has worked at a mobile carrier would ever think that they're ready to be high-value targets. So it's puzzling that the banks are so eager to put them in that position.

The order of shaming should be: 1. Businesses using insecure channels to do authentication and validation. 2. Mobile carriers

Oh you're right, I had it backwards. Perhaps the carriers should be trying to PR-hack this into more people's minds.

I'm imagining an authorized pen-tester program which lets authenticated users achieve an atomic sim-swap (i.e. the creds were intercepted but the swap-back occurred immediately after, so as not to deny additional service to the victim).

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#312

Might it be time for the US government to step in using eminent domain, seize the company and merge it into a different provider? Are other providers more secure or do we just hear about T-Mobile the most? Who should take over T-Mobile? [Edit] The more I think about this, perhaps another path to resolution would be to remove limited liability protections from companies that repeatedly put their customers at risk, esp…

And then we'd be down to what, two wireless carries in the US? AT&T already tried to acquire/merge with T-Mobile some years ago but it didn't go through. I forget why, but probably due to antitrust issues. And wasn't Sprint just acquired/merged with not long ago, by T-Mobile IIRC?

> I forget why, but probably due to antitrust issues. And wasn't Sprint just acquired/merged with not long ago, by T-Mobile IIRC?

Yes and yes. We're down to three big mobile telecoms now, ATT, Verizon, T-mobile/Sprint. At least MVNO's are allowed though, plenty of those.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#313

Earlier quoted context omitted.

One way to do so would be to make it so wireless companies can lose access to spectrum as a consequence of customer data breaches. Let someone else who can keep customer data secure have it instead.

That ultimately hurts customers more than the data breach. Limiting access means less availability for customers. If all the customers leave, you’ve just contributed to a monopoly/oligopoly.

Or reserve it for the next company that could pony up at a significant discount.

Look - too big to fail means we let too many companies merge. This isn't a healthy situation that losing T-Mobile means having no competition left. We should probably unwind some mergers first.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#314
post #65

I was a victim of this last October and November on a T-Mobile number. This is what occurred: - My Gmail account was compromised - My Amazon account was compromised In Gmail, they added a filter to hide any shipping or customer service messages from Amazon. In Amazon, every other day, they placed an order for a ~500 USD GoPro device, delivered to an address in NYC. This address changed with every order. Both password…

> In Gmail, they added a filter to hide any shipping or customer service messages from Amazon. I gotta admit, that's pretty clever. Crude, but effective.

Another common technique is a filter to forward all mail. Hard to notice. I ought to go check right now...

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#316
post #84
post #8

> T-Mobile declined to answer questions about what it may be doing to beef up employee authentication. But Nicholas Weaver, a researcher and lecturer at University of California, Berkeley’s International Computer Science Institute, said T-Mobile and all the major wireless providers should be requiring employees to use physical security keys for that second factor when logging into company resources. > “These breaches…

I think why regulation hasn’t happened is because the computer industry has changed so quickly. Two-factor auth wasn’t even a commonly accepted best practice two decades ago. And regulation takes a while to create and put into practice and with the rate things are going, by the time regulation has been out in place, the current best practices will have changed. Whereas writing regulation on building bridges is easy b…

My dad worked in telecom for a baby bell and they had 2FA fobs since at least 2004 (probably earlier but I didn’t see it until then). He wasn’t even in a consumer facing company, they made equipment for other companies. If they could implement this 20 years ago, there’s no excuse for Tmobile today.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#317
post #137

Earlier quoted context omitted.

Interesting... I had something similar happen to me, with minimal outward, acute damage (e.g., running up bills on random credit cards). It is reasonable to assume my entire identity is compromised. Sorry this happened. How do you know T-Mobile was the entry point, and not say, Google (e.g., Google Chrome, Google Ads)? What type of phone did you have (e.g., Android or iPhone)? What is your browser and Search Engine o…

I assumed it was T-Mobile after I wiped the phone and had the follow-up incident where a verification code via SMS was successfully verified. I used an iPhone, Safari mobile, Google search engine.

There's also this giant vulnerability with Apple Webkit, across all devices, that was patched 13 February 2022: https://9to5mac.com/2023/02/13/macos-13-2-1-webkit-security-....

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#318

Earlier quoted context omitted.

Thanks. I have Google backup codes as well as multiple Authy installations, Google prompt and a recovery email address so I guess I should be covered :)

What is "Google prompt" here?

It’s a notification pop-up the Google mobile app can send, asking for login confirmation.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#319
post #270
post #242

Earlier quoted context omitted.

As an InfoSec professional, what you describe sounds more like a device-level compromise of your iphone, perhaps through a malicious app, or link you clicked. What your experienced can't be done with just a sim swap attack, as you would have lost access to your phone number. And it can't be done with the described T-Mobile hack, as it would have given the hackers silent access to your texts, so they could have reset…

Read up on credential stuffing, this is increasingly common. With all the recent breaches, there are groups that use old passwords to quickly identify MFA locked accounts behind re-used passwords. These lists are then sold to people who will, one at a time, pay about 10k for a SIM swap on individually targeted users. There are lists floating around with 10s of thousands, or hundreds of thousands of users with known p…

The victim (ctvo) claims in another comment down the thread that he had a unique Gmail password not re-used on any other service. So I wrote my comment assuming this is true. But, indeed, if his Gmail password was weak and guessable, then the T-Mobile hack would have allowed the hackers to validate MFA and log in.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#320
post #242

Earlier quoted context omitted.

As an InfoSec professional, what you describe sounds more like a device-level compromise of your iphone, perhaps through a malicious app, or link you clicked. What your experienced can't be done with just a sim swap attack, as you would have lost access to your phone number. And it can't be done with the described T-Mobile hack, as it would have given the hackers silent access to your texts, so they could have reset…

Honestly I’m a bit concerned an infosec professional has reached for “iOS device compromise” over a…more common and lower-effort explanation.

The victim (ctvo) claims in another comment down the thread that he had a unique Gmail password not re-used on any other service. I commented assuming this premise is true.
Post reply on HN