Live data from Hacker News

Google Fi seemingly affected by latest T-Mobile data breach

9to5google.com

11–20 of 88 posts

Re: Google Fi seemingly affected by latest T-Mobile data breach

#12
post #6

The same probably goes for other MVNO carriers such as Mint and Ting. The PII and billing data is with the MVNO carriers. I buy my SIM cards anonymously. I never use cellular near my house and only use it for data over a VPN. So it would not affect me if all of their data was breached.

> only use it for data over a VPN Unless you run this yourself, I don't understand why you nor anyone thinks that adds to their data integrity? VPNs can, have, and are the subject of break-ins and have their own agenda and or government oversight. People think that VPNs are this magical black box that makes you secure and private, because the YouTube ads told everyone so, the reality is that you are just adding an ex…

Yes I know the trust requirement of VPN's and hear this all the time. I run my own VPN. The point is that the carrier has too little data to identify me.

Re: Google Fi seemingly affected by latest T-Mobile data breach

#13
post #5

Not everyone got this version of the notice. Here's a reddit user who posted [1] that they were SIM swapped: > Additionally, on January 1, 2023 for about 1 hour 48 minutes, your mobile phone service was transferred from your SIM card to another SIM card. During the time of this temporary transfer, the unauthorized access could have involved the use of your phone number to send and receive phone calls and text message…

> could have involved the use of your phone number to send and receive phone calls

Surely from their logs they know if these calls/texts happened?

If, during that period no calls/sms's occurred, then there has been no breach - the attacker was close to their target, but walked away with nothing.

If messages/calls were made, the user really needs to know who they were to/from to make any informed decisions. And Google has those logs.

Re: Google Fi seemingly affected by latest T-Mobile data breach

#14
post #2

A reasonable headline could state "Google Fi essentially not affected by latest T-Mobile data breach". Look at the data "breached": > limited data including when your account was activated, data about your mobile service plan, SIM card serial number, and active or inactive account status. > It does not contain your name, date of birth, email address, payment card information, social security number or tax IDs, driver…

[flagged]

Re: Google Fi seemingly affected by latest T-Mobile data breach

#15
post #6

The same probably goes for other MVNO carriers such as Mint and Ting. The PII and billing data is with the MVNO carriers. I buy my SIM cards anonymously. I never use cellular near my house and only use it for data over a VPN. So it would not affect me if all of their data was breached.

> only use it for data over a VPN Unless you run this yourself, I don't understand why you nor anyone thinks that adds to their data integrity? VPNs can, have, and are the subject of break-ins and have their own agenda and or government oversight. People think that VPNs are this magical black box that makes you secure and private, because the YouTube ads told everyone so, the reality is that you are just adding an ex…

In the context of not trusting your ISP (the mobile provider in this case) a VPN provides a lot of security. You aren’t “adding an extra point of trust or potential failure”, you are choosing to trust your VPN provider instead of your ISP.

Re: Google Fi seemingly affected by latest T-Mobile data breach

#16
post #5

Not everyone got this version of the notice. Here's a reddit user who posted [1] that they were SIM swapped: > Additionally, on January 1, 2023 for about 1 hour 48 minutes, your mobile phone service was transferred from your SIM card to another SIM card. During the time of this temporary transfer, the unauthorized access could have involved the use of your phone number to send and receive phone calls and text message…

> could have involved the use of your phone number to send and receive phone calls Surely from their logs they know if these calls/texts happened? If, during that period no calls/sms's occurred, then there has been no breach - the attacker was close to their target, but walked away with nothing. If messages/calls were made, the user really needs to know who they were to/from to make any informed decisions. And Google…

Straight to a write only bucket in Maryland.

Re: Google Fi seemingly affected by latest T-Mobile data breach

#17
post #6

The same probably goes for other MVNO carriers such as Mint and Ting. The PII and billing data is with the MVNO carriers. I buy my SIM cards anonymously. I never use cellular near my house and only use it for data over a VPN. So it would not affect me if all of their data was breached.

Lol this is not the same with most people. Pretty incredible if true. Timing attacks are pretty powerful though. Only one person has likely been to all the same places at you at the same time over the past week.

I don't have a regular movement pattern and only activate the SIM when needed. I also rotate SIM's with my partner to confuse things more. We are part of a budding trend.

Re: Google Fi seemingly affected by latest T-Mobile data breach

#18
post #6

The same probably goes for other MVNO carriers such as Mint and Ting. The PII and billing data is with the MVNO carriers. I buy my SIM cards anonymously. I never use cellular near my house and only use it for data over a VPN. So it would not affect me if all of their data was breached.

[deleted]

Re: Google Fi seemingly affected by latest T-Mobile data breach

#19
post #6

The same probably goes for other MVNO carriers such as Mint and Ting. The PII and billing data is with the MVNO carriers. I buy my SIM cards anonymously. I never use cellular near my house and only use it for data over a VPN. So it would not affect me if all of their data was breached.

>The same probably goes for other MVNO carriers such as Mint and Ting. The PII and billing data is with the MVNO carriers.

Are you sure? In the previous T-Mo breach Ting claimed the opposite.

https://help.ting.com/hc/en-us/community/posts/4405384603291...

>the kind of Ting Mobile customer data at issue in this data breach is not stored on T-Mobile servers. Ting Mobile holds its own customer database on our own servers. The kind of data T-Mobile does have access to are things that are network-specific, like your phone number, SIM card number, usage data, and IMEI.

>T-Mobile does not have access to the Ting Mobile database of names, email addresses, credit card information, etc. Your information is protected and secure from what the hackers claim to have collected.

Re: Google Fi seemingly affected by latest T-Mobile data breach

#20

When will T-Mobile take accountability for their repeated data breaches and fix the systemic issues? Is there anyone in the company who cares enough to do something?

The annual T-Mobile data breach is a tradition at this point. 2022 was set to break that tradition but the breach just happened to run a few weeks late.
Post reply on HN