Live data from Hacker News

Hackers claim they breached T-Mobile more than 100 times in 2022

krebsonsecurity.com

331–340 of 342 posts

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#331
post #260

Earlier quoted context omitted.

Do you happen to know if they allow you to also totally disable SMS 2FA? I know that Vanguard, for instance, supports non-SMS 2FA but doesn't let you disable SMS as a fallback (and I'd rather not just totally remove all phone numbers, but maybe I have to...).

I believe you can remove SMS fallback now on Vanguard.

Neat, thank you! I'll give it a try.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#334
post #242

Earlier quoted context omitted.

As an InfoSec professional, what you describe sounds more like a device-level compromise of your iphone, perhaps through a malicious app, or link you clicked. What your experienced can't be done with just a sim swap attack, as you would have lost access to your phone number. And it can't be done with the described T-Mobile hack, as it would have given the hackers silent access to your texts, so they could have reset…

Honestly I’m a bit concerned an infosec professional has reached for “iOS device compromise” over a…more common and lower-effort explanation.

Do share the explanation with us if you would kindly so please.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#335

Earlier quoted context omitted.

> In Gmail, they added a filter to hide any shipping or customer service messages from Amazon. I gotta admit, that's pretty clever. Crude, but effective.

Another common technique is a filter to forward all mail. Hard to notice. I ought to go check right now...

I think Gmail has a big yellow notice in your account for 7 data after a new forwading e-mail address is added. That of course falls apart when you use an external client but there’s that.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#336

Earlier quoted context omitted.

It’s a notification pop-up the Google mobile app can send, asking for login confirmation.

I see, but doesn't have the same issue as sending an SMS to the phone if the phone has been stolen in that the thief can just say "yes" to the prompt?

No, it's not quite the same issue. SIM swap works remotely without anyone getting a hold of my phone.

A stolen phone can of course be a problem as well, but at least it's somewhat under my control and I may notice pretty quickly when it's gone.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#337

Earlier quoted context omitted.

Should we throw the President in jail if the government gets breached?

no, of course not. (nice straw-man attempt, btw) Just the way boards of companies have fiduciary duty, there should be some of sort customer information protection duty that companies are responsible / liable for. basic security practices are being neglected at far too many companies.

Really not trying to strawman. You literally said an executive or two should be thrown in jail if their organization was breached. So which government executive would you "throw in jail" if their organization was breached?

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#338
post #194
post #151

Earlier quoted context omitted.

How would you know unless you check your credit card statement every day?

FWIW, some banks will let you setup email alerts for when your cc is used, or used over a certain threshold.

I have mine setup to send me a text message for every transaction. However, I suppose I might stop getting the texts if my number was compromised.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#339

Earlier quoted context omitted.

Google Voice isn't a wireless carrier. VoIP only.

This is part of my question. How does Google provision VoIP numbers? When someone calls / texts a VoIP number from a normal number, that call / SMS travels over normal wireless infrastructure. So VoIP numbers are still connected to the same infra, right?

As I understand it, yes, but not through a wireless carrier. They'd tie into the infrastructure somewhere else. They'd be more of a peer with Tmobile then a customer.
Post reply on HN