Live data from Hacker News

T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

wsj.com

121–130 of 138 posts

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#121

"A booming industry of cybersecurity consultants, software suppliers and incident-response teams have so far failed to turn the tide against hackers and identity thieves who fuel their businesses by tapping these deep reservoirs of stolen corporate data." Sure, blame the consultants with their "booming industry". I'm sure T-Mobile spent adequate amounts of money on securing their data, hired all the best people, and…

[deleted]

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#122

"A booming industry of cybersecurity consultants, software suppliers and incident-response teams have so far failed to turn the tide against hackers and identity thieves who fuel their businesses by tapping these deep reservoirs of stolen corporate data." Sure, blame the consultants with their "booming industry". I'm sure T-Mobile spent adequate amounts of money on securing their data, hired all the best people, and…

I don't doubt that T-Mobile could have done more, but it's also frustrating to see this trope that spending more money on security is some type of silver bullet. It's not. I've been in security for over a decade. I currently work at a FAANG with nearly unlimited security budget. Previously I worked at another major tech company with nearly unlimited security budget. Before that I was a consultant and consulted at com…

[deleted]

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#123

Earlier quoted context omitted.

Everyone always talks about making penalties more severe for data leaks. I have to wonder what the consequences of that would be. Bankrupting your competitor might become as easy as paying a few bitcoins to a foreign mercenary. I think better security and encryption protocols need to be developed that mitigate the severity of a single leak. Without more compartmentalization of data and more control put into the hands…

> Bankrupting your competitor might become as easy as paying a few bitcoins to a foreign mercenary. This would result in insurance policies to guarantee against that outcome. Those policies in turn would introduce both costs and practices across industries that would improve the security of all the insured (and indirectly, their customers). Unlike hiring a Rainmaker to look nice for the C-suite, imposing these costs…

> This would result in insurance policies to guarantee against that outcome. Those policies in turn would introduce both costs and practices

Equifax had over $100mm of cybersecurity insurance coverage [1]. The breach cost them over $2bn, including fines. This isn't purely a motivation problem.

[1] https://www.bizjournals.com/atlanta/news/2020/02/13/equifax-...

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#124
post #23

What I don't understand is why the hacker (whose full name is used in the article - alias?) is being public about this? Shit security or not, they made a clear cut black hat move purely for money. Or I suppose the other factor is fame/infamy. Pretty sure there are at least a few pissed off hackers among those 50M people who would want to track this person down digitally and pull something as retaliation.

From the article "John Binns, a 21-year-old American who moved to Turkey a few years ago" I'm assuming it is the Turkey thing, probably counting on that to be a significant barrier. Yes they have extradition but I've also heard that Turkish authorities are quite amenable to bribes as well.

> Yes they have extradition but I've also heard that Turkish authorities are quite amenable to bribes as well

Turkey is also a NATO member. If T-Mobile can get the U.S. government to plead their case, that could generate serious impetus for action from the top.

Also, if you're in a country whose officials take bribes, advertising that you're (a) vulnerable and (b) potentially in possession of cash is dangerous.

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#125

Earlier quoted context omitted.

> finding devs (or any other role) that understand security is very, very difficult. At what level? Are we talking like knowing the different ways to mitigate XSS and other basic OWASP top-10 style things, or having the ability to find the next Spectre or Meltdown?

We recruit primarily for mid-to-senior level roles (5-15 yrs experience), and it's the former. I get a lot of candidates that can recite what XSS is at a high level, but for example struggle to explain the things to watch out for that would indicate a possible XSS vulnerability. One of the other issues I see is that we should be able to take the above-described candidate, which is maybe not exactly what we need but s…

So basically it is a Chicken and Egg Problem?

Something needs to be done at a fundamental level and finding some easier qualification in terms of security professional before this problem could be fixed.

One easy way to fix it would be market economics. Make senior security roles paid grade a lot higher than comparative other similar software engineering roles. These incentives should balance things out in time.

Otherwise I am looking at security professional death spiral.

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#126

Earlier quoted context omitted.

This makes no sense at all---you're implying that the bad guys somehow have a monopoly on innovation and effectiveness, when in reality, there is just more upside for them to steal sensitive info than there is downside for companies to protect it. If T-Mobile's latest data breach led to them getting fined, say, $5 billion, I promise you it would be the last.

It would be the last for T-Mobile because it would end T-Mobile. But it wouldn't be the last breach ever. I could give $5 billion to my FAANG right now and I bet we'd still be breached (hell, I'm pretty sure we already have that budget in my FAANG's security department). The US DoD already has a cyber security budget of $10 billion, and they still get breached. You underestimate the amount that these companies care a…

Something like 20 years ago I was doing research on AntiVirus and Security option, defaults and products. Trying to find the perfect solution.

I remember my final conclusion, "Security" is a mindset, not a Product.

I guess this rhymes with what you said.

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#127
post #99

Earlier quoted context omitted.

Eh, it's both. Other departments don't necessarily focus on security (and leetcode is certainly an idiotic way of hiring, IMO). But even in my department (where we explicitly don't use leetcode and do prioritize based on security expertise and offer a huge premium for it), we are significantly under our target headcount because finding devs (or any other role) that understand security is very, very difficult.

Could this be because so many companies don't focus enough on security? So there isn't enough collective experience out there, making it hard to find those that do have the knowledge and experience.

I think partly so, yes. I also think in general the security industry is very bad at increasing the level of collective experience, so it sort of just stagnates.

Other fields like web development, consulting, engineering, lawyers, medical field etc all have very established career development pipelines, where you can join as a junior employee and learn on the job from those around you to become a better professional.

Security on the other hand lacks this. In the vast majority of organizations I've been in, security roles are something that you are expected to enter with an already established level of experience, and then you are dropped on a project by yourself with little mentorship or training. This makes it almost impossible to bring new people into the field.

At my company, we have a "security champions" program that is intended to allow software engineers to dedicate some of their time to security and help their team think through security challenges. But we really struggle with this program, because my company pretty much just hopes that the engineers signing up to be champions are already experienced in security. If they are not, we do not have processes in place to train them, even if they do want the training.

And what's worse, is that I even see resistance to making it easier for junior people to learn security. If you spend much time on r/cybersecurity, a common thing you will see is people insisting that security should not be an entry level job, and that everyone should be required to spend 5-10 years as a sysadmin before you're even allowed to apply for a security role. I think that's ridiculous, and not only for the reason that being a sysadmin has a lot less overlap with the world of security than people like to think it does.

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#128

Been a T-Mobile customer for ages. Sim swaps are too easy. 2 factor is a joke. This is like the 3rd time my data has been lifted. But I stay with them, why? Because I have 3 free lines, unlimited everything, for $32 a month. They have crazy phone trade in deals from time to time, T-Mobile tuesday usually nets me 15c off per gallon at shell. Am I happy that they keep getting hacked? Absolutely not, but I'm happy prett…

how on earth do you have 3 lines with unlimited data for 32 a month?

I have 6 lines, "unlimited" with T-Mobile for around $130 used by various family members. Can't find a better deal than that.

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#129

"A booming industry of cybersecurity consultants, software suppliers and incident-response teams have so far failed to turn the tide against hackers and identity thieves who fuel their businesses by tapping these deep reservoirs of stolen corporate data." Sure, blame the consultants with their "booming industry". I'm sure T-Mobile spent adequate amounts of money on securing their data, hired all the best people, and…

I don't doubt that T-Mobile could have done more, but it's also frustrating to see this trope that spending more money on security is some type of silver bullet. It's not. I've been in security for over a decade. I currently work at a FAANG with nearly unlimited security budget. Previously I worked at another major tech company with nearly unlimited security budget. Before that I was a consultant and consulted at com…

A big budget doesn't guarantee good security, but a low budget pretty much guarantees poor security.

Re: T-Mobile Hacker Who Stole Data on 50M Customers: ‘Their Security Is Awful’

#130
post #78

Earlier quoted context omitted.

So true. When I was a student, I aced most of my classes from math theories to ee. But took one cryptography class and everything went over my head. To this day, its hard for me to tell during hiring what makes a good security hire.

And yet, (correct me if I'm wrong), a good security person does not need to understand cryptography. He should have some basic understanding of how to apply it, but the knowledge of it's internals and the math behind it is pretty much useless.

true, crypto(graphy - wow, been so long since i've typed it that I've just realized crypto has now been bogarded for something else). theory vs applied but I think its still true the mindset of a hacker is still very different. ie similar to the whole IT vs dev
Post reply on HN