Live data from Hacker News

Hackers claim they breached T-Mobile more than 100 times in 2022

krebsonsecurity.com

201–210 of 342 posts

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#201
Seems plausible. Suffered a SIM-hijack attack via T-Mobile a few years ago. Set a giant extra arbitrary password for account changes after that - but they essentially don't ask for it. Fairly regularly they show notices of breaches via email or when logging in.

Don't use a mere mobile number for the backup access to anything inportant!

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#202

I see people jumping towards regulation, but that has the side-effect of making it even more difficult for there to be any competition against these monopolies. What we really need is legitimate competition, to enable consumers to vote with their wallet and move to a competitor that takes the security of their customer's private data seriously.

> making it even more difficult for there to be any competition against these monopolies

If your snappy upstart cellular network can't afford to give out Yubikeys to employees, I don't want you interconnecting with the rest of the phone system.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#203

Earlier quoted context omitted.

I can use my phone number for 2FA and/or as a recovery phone number. Would you advise to remove it from both places or just from 2FA?

Remove it from both. However make sure that you have quite a lot of backups of your 2FA backup keys, and maybe even one offline backup of your seed, if you lose them, the account is gone (which is a good thing, I guess).

Thanks. I have Google backup codes as well as multiple Authy installations, Google prompt and a recovery email address so I guess I should be covered :)

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#204

Which cell phone network would you guys recommend for people who care about security?

Any network that isn't shared with your personal phone number. That is: if you have a dedicated number for SMS 2FA, it will show up in fewer places where the hackers might find it. It's easier to monitor for breaches, and replacing it is a simple matter of updating your accounts - no need to worry about lost contacts, friends, bills, etc.

Although, "bills" reminds me - a lot of companies overload the use of 2FA SMS for both identification and 2FA purposes, not to mention most customer service centers expect the call to originate from the same number that receives 2FA SMS messages for authenticating to the account being serviced.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#205
post #198
post #8

> T-Mobile declined to answer questions about what it may be doing to beef up employee authentication. But Nicholas Weaver, a researcher and lecturer at University of California, Berkeley’s International Computer Science Institute, said T-Mobile and all the major wireless providers should be requiring employees to use physical security keys for that second factor when logging into company resources. > “These breaches…

Yubikeys and macs are not magic solutions. That's not good security thinking. The same passwordless b.s. that's spreading like cancer is another thing. Bigcorp networks are emergent, not pieced together. Threat actors just need one or two flaws. Case in point, the mac and yubikey corp with big fat wallet that was hacked: uber. Everyone is a backseat driver with silverbullet solutions, meanwhile there are decades of r…

While normally I would agree wholeheartedly with this, in this very instance I see meaningless abstraction in service of justifying consumer harm. The phishing TTPs outlined in the article can be mitigated with hardware keys, and the places in the corporate network where they must be part of auth workflows can be identified. There are people whose job this is in corporate networks of all levels of piecemeal quagmires. T-Mobile probably has people working on this now.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#206

I see people jumping towards regulation, but that has the side-effect of making it even more difficult for there to be any competition against these monopolies. What we really need is legitimate competition, to enable consumers to vote with their wallet and move to a competitor that takes the security of their customer's private data seriously.

Ah, the libertarian dream. Unfortunately, utilities such as phone service are often close to natural monopolies, due to the infrastructure overhead.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#207
post #152
post #73

Earlier quoted context omitted.

I use Google voice for everything... except my bank because they said using T-Mobile is so much more safer than Google so I had to switch back

The prohibition against using a VoIP number for banking purposes is stupid. They already have the full battery of KYC info on me: if I want to use a VoIP number for 2FA (because they are so behind the times they don't support FIDO or even TOTP) then unless law says they cannot they need to allow it. And while on the topic of banks, most will suspend access to your online portal if you log in with a VPN. Give me a ban…

Both Fidelity and Schwab allow non-SMS 2FA.

They both use Symantec VIP but it’s fairly easy (for developers at least) to export those tokens and import them into something like Authy, Google Authenticator etc.

https://ketanvijayvargiya.com/257-symantec-vip-authy/

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#208

I've been thinking about this a bit more and I think the right path forward is to impose the same fiduciary liabilities and regulations on cellular providers that banks enjoy . Phones are used as authentication devices for bank transactions. If cellular providers have to go through all the same audits of controls as banks and share the same fiduciary liabilities that may raise the bar for phishing attempts. This may…

I actually think we should just divest all security tasks from cellular providers. They are clearly bad at it and I don't think they ever really pretended it was a core competency. Reforming them would take far longer than just switching to the available alternatives, and probably would not work as they would just lobby any regulations down to be toothless.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#209
post #202

I see people jumping towards regulation, but that has the side-effect of making it even more difficult for there to be any competition against these monopolies. What we really need is legitimate competition, to enable consumers to vote with their wallet and move to a competitor that takes the security of their customer's private data seriously.

> making it even more difficult for there to be any competition against these monopolies If your snappy upstart cellular network can't afford to give out Yubikeys to employees, I don't want you interconnecting with the rest of the phone system.

Also, startups have such an advantage now that there is an ecosystem of COTS and SaaS tooling that can help you do a complete integration strategy. It's arguable MFA regulations would advantage startups because they don't have to deal with the complexity of legacy network piecemeal integration.

I planned and did the roll out of Yubikeys at the last place I worked, before there was a dollar in sales, and the lifecycle could be supported with 2 people (minutes at most out of each day for support) and an integration to our HR platform that automated procurement and mailing of keys.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#210
post #8

> T-Mobile declined to answer questions about what it may be doing to beef up employee authentication. But Nicholas Weaver, a researcher and lecturer at University of California, Berkeley’s International Computer Science Institute, said T-Mobile and all the major wireless providers should be requiring employees to use physical security keys for that second factor when logging into company resources. > “These breaches…

After an incident our compliance people told us we cannot have different 2FA options for the same user, so yes in fact if you need to use a legacy system ever then you cannot have a yubikey enabled anywhere.
Post reply on HN