Live data from Hacker News

Hackers claim they breached T-Mobile more than 100 times in 2022

krebsonsecurity.com

41–50 of 342 posts

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#41
post #8

> T-Mobile declined to answer questions about what it may be doing to beef up employee authentication. But Nicholas Weaver, a researcher and lecturer at University of California, Berkeley’s International Computer Science Institute, said T-Mobile and all the major wireless providers should be requiring employees to use physical security keys for that second factor when logging into company resources. > “These breaches…

You assume that regulation can just make security magically happen. I see no reason to assume that premise to be correct in practice. It's not like the US Government hasn't been breached countless times or had Supreme Court opinions leaked; and it's not like corporations that really tried and should be examples of best practice haven't also been breached. Also, what law can prevent insider attacks? There's already pl…

Don't underestimate the value of checking all the security compliance check boxes. It solves what really matters - protecting executives from prosecution and/or being dragged in front of Congress to testify.

Seriously though, so long as cybersecurity insurance and "industry best practices checkbox management" is easier and/or cheaper than actual meaningful security measures, it will never be solved.

Worse, when a meaningful security measure that could actually make a difference collides with something in a best practices document, you know who will lose.

I'm not cynical at this point, no...

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#42

They will pay the fines and keep doing business happily and another "we're sorry, it won't happen again..." The joys of being too big to fail.

Increase the fines tenfold or up them an order of magnitude till it’s no longer just a negligible cost of doing business

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#43
post #30

Might it be time for the US government to step in using eminent domain, seize the company and merge it into a different provider? Are other providers more secure or do we just hear about T-Mobile the most? Who should take over T-Mobile? [Edit] The more I think about this, perhaps another path to resolution would be to remove limited liability protections from companies that repeatedly put their customers at risk, esp…

What should not have happened is the Sprint T-Mobile merger. Like when Wells Fargo bought the failed bank (forget which one) after 2008, Wells Fargo went from a reliable company to all kinds of suspect things going on with our account. So far T-Mobile has been fine for us but we are seeing some marketing things floating around suggesting the Sprint influence might be having a negative impact on T-Mobile. I miss John…

Those were awful mergers. Supposedly the US government has reduced the amount of rubber-stamping of these mergers and are said to be scrutinizing them more now. I suppose time will tell. I don't know how else to get real results on fixing poor security practices other than to remove all immunity and limited liability protections from businesses that repeatedly put their customers in harms way and that would have other incredibly bad ramifications.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#44
The article doesn't make it clear which T-Mobiles are affected.

The article seems to be US-centric, so, only T-Mobile US? Or all 13 Deutsche Telekom subsidiaries [1]?

What about T-Mobile Netherlands, which was sold off by Deutsche Telekom but retains the T-Mobile name?

[1] https://en.wikipedia.org/wiki/T-Mobile#Operations

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#45

It is an open secret that criminal groups also pay unscrupulous T-Mobile employees to assist with SIM-swap attacks. I am not sure at what scale this happens, as those instances _should_ be easy to trace and prosecute. But I have seen evidence of criminals reaching out and offering "side work" on the T-mobile subreddits, as an example. In those cases, hardware keys for employees would not help.

> those instances _should_ be easy to trace and prosecute

I suspect that the employees aren't merely doing a sim swap attack with their work login credentials. Like you say, they'd clearly get fired/prosecuted for that.

Instead, I suspect criminal X buys a nice thing delivered to employee Y's house. Then, criminal X phones the helpdesk repeatedly till they get connected to employee Y during working hours. Then, they claim to own the phone number of victim Z, but have lost the phone, their id and everything else. But they manage to tell employee Y the answer to two of the secret questions "What is your gender", and "Did you use the internet in the last month?". The employee uses this, together with their judgement to proceed, according to company policy, and issue a new eSIM.

Later, when anyone finds out, the call is listened to, and the employee can legitimately say they were just following policy.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#49
post #21

Was thinking about moving a line to Google Fi for this reason. I know they just resell T-Mobile bandwidth, but would they provide better account level security? Is it common for Google Fi customers to get SIM swapped?

yup https://www.bleepingcomputer.com/news/security/google-fi-dat... my friend had google fi and was caught in this, among other things they had their instagram taken over. scary few days. thankfully their roommate works at meta... I think the only way to be really safe is to use one of the smaller MVNOs and never ever ever reveal who your carrier is

Thanks! Based on that article it seems that anyone who's reselling T-Mobile service would be vulnerable.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#50

You know, I’m starting to become slightly more serious about switching carriers solely based on how terrible it would be to experience SMS/Call diverting of my number. While I use a yubikey, OTP (where possible), and unique passwords…there’s still places where I have no choice and my number is my auth (or stupidly a reset option). I genuinely am happy with TMO service in the US, and frankly abroad it’s excellent…but…

TMobile seems to be particularly bad right now, but Verizon and AT&T aren’t necessarily good. The weak link is usually retail or channel. TMobile is in a high growth phase, so I’d hazard to guess they are more disorganized. Switching to Verizon may reduce exposure, but they have their own similar issues - an aggressively dumb carrier employee is capable of almost anything.

As sad as it is to write this, Apple corporate lines are Verizon - though they also have ATT available if you need it or have a preference. I only say this as I don’t know of any major corporation who picks TMO as their company lines.

All this to say, I trust ATT and Verizon slightly more than T-Mobile

Post reply on HN