Live data from Hacker News

Hackers claim they breached T-Mobile more than 100 times in 2022

krebsonsecurity.com

1–10 of 342 posts

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#2
I don’t doubt it. My cell phone stopped working for a day, I called in and talked to somebody who I could barely understand and knew very little about basic security. I tried to explain multiple times that my account was probably SIM swapped and the support person completely ignored this security concern and just said I have fixed the issue on my end anything else I can help you with? Please rate me 5 star in the coming support survey.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#7
You know, I’m starting to become slightly more serious about switching carriers solely based on how terrible it would be to experience SMS/Call diverting of my number.

While I use a yubikey, OTP (where possible), and unique passwords…there’s still places where I have no choice and my number is my auth (or stupidly a reset option).

I genuinely am happy with TMO service in the US, and frankly abroad it’s excellent…but I’d be lying if every single article I see about their security breaches reminds me I may be on borrowed time myself.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#8
> T-Mobile declined to answer questions about what it may be doing to beef up employee authentication. But Nicholas Weaver, a researcher and lecturer at University of California, Berkeley’s International Computer Science Institute, said T-Mobile and all the major wireless providers should be requiring employees to use physical security keys for that second factor when logging into company resources.

> “These breaches should not happen,” Weaver said. “Because T-Mobile should have long ago issued all employees security keys and switched to security keys for the second factor. And because security keys provably block this style of attack.”

At what point do we consider industry self-regulation on this a total failure? You don't need to make Yubikeys a part of every auth workflow in your corporate enterprise if there are legacy systems/integrations, but you should at least do it for the things that can change customer mobile subscription details and there can't be any excuse.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#10
post #9
post #3

[flagged]

You didn't read the article. This isn't about a data leak, it's about being able to intercept SMS for any T-Mobile phone number.

Surely any enterprising criminal would do both sell and exploit users data…
Post reply on HN