Live data from Hacker News

Google Fi seemingly affected by latest T-Mobile data breach

9to5google.com

61–70 of 88 posts

Re: Google Fi seemingly affected by latest T-Mobile data breach

#61
post #21

Earlier quoted context omitted.

The why is obvious. People will lose their 2FA. It's a fact of life. Lost keys with your yubikey. Broken phone without a backup of your totp. Etc. After that, how do you prove that someone owns their account? Send a photocopy of your passport? No way to edit a picture, right? Answer some security questions, which you certainly forgot the answer to. And people are likely using the same questions with the same answer o…

The solution is a government issued key pair. Probably on a Yubikey type of device. Replacing a lost one of those is then the same process as replacing a lost driver's license / passport / other government issued identification. By 2023 it's high time for these forms of identification to catch up with the digital age. It's high time to end the joke of verifying identity by birthday, SSN, "in-security questions", and…

I can't say the idea of a verifiable government id being demanded by every social media or other sign up sounds that thrilling to me. It'll just be facebook demanding a scan of your driver's license in a different form. The SMS verification step where you phone number is demanded "only for security" (and then used for advertising 10 minutes later) is bad enough, but at least it is still possible (if onerous) to get some some separation there.

I'd honestly just prefer TOTP or hardware tokens be mandated as an option for 2FA if you offer it.

Re: Google Fi seemingly affected by latest T-Mobile data breach

#62
post #26

Earlier quoted context omitted.

Solution is multiple yubikeys or printing out backup codes.

How are you handling multiple Yubikeys? I'm doing it personally and it's so annoying that I can't imagine recommending this to anyone else. Since I'd hate to lose access to everything if my house burns down, I keep a key outside of the home. Of course, for that key to be useful, I need to update it whenever I use my key on a new site/service. Dropping everything to go fetch my key is inconvenient, so I keep multiple…

Fireproof safe, and living in an area where the fire department would be able to get the fire under control fast enough that I would hopefully not need 1/10th of the capability of that safe.

Edit: also, if your house burns down, won’t you probably have your keys on you if you’re not home?

Re: Google Fi seemingly affected by latest T-Mobile data breach

#63
post #15

Earlier quoted context omitted.

In the context of not trusting your ISP (the mobile provider in this case) a VPN provides a lot of security. You aren’t “adding an extra point of trust or potential failure”, you are choosing to trust your VPN provider instead of your ISP.

HTTPS already provides the same protection. VPN doesn't add anything for that. About the only meaningful feature VPN provides is presenting a different IP address to the server. VPN provides negligible extra security for most people, while adding extra exposure.

I agree that VPNs are generally over-hyped, but they absolutely offer an increase in protection here.

ISPs have historically done slimey things like hijacking DNS, and HTTPS leaks tons of metadata like what sites you’re browsing and for how long, and what user agents you have can easily be fingerprinted. And there are still too many IoT and mobile apps that don’t strictly use TLS for everything.

Re: Google Fi seemingly affected by latest T-Mobile data breach

#64

When will T-Mobile take accountability for their repeated data breaches and fix the systemic issues? Is there anyone in the company who cares enough to do something?

The annual T-Mobile data breach is a tradition at this point. 2022 was set to break that tradition but the breach just happened to run a few weeks late.

The FTC filing says they first got popped in November 2022, so it’s still an annual tradition.

Also, they only report the breaches they actually know about. From my understanding of T-mobile, they probably only find a breach when someone completely stumbles into it. For every one they discover I bet there’s 10 they don’t, hah

Re: Google Fi seemingly affected by latest T-Mobile data breach

#65
Because it’s buried a few links deep:

T-Mobile detected the breach January 5 and shut it down “within a day”

But

It started approximately November 25th, so the attackers were there for at least a month and a half, pulling 37,000,000 records before anyone noticed.

Re: Google Fi seemingly affected by latest T-Mobile data breach

#66
post #21

Earlier quoted context omitted.

The why is obvious. People will lose their 2FA. It's a fact of life. Lost keys with your yubikey. Broken phone without a backup of your totp. Etc. After that, how do you prove that someone owns their account? Send a photocopy of your passport? No way to edit a picture, right? Answer some security questions, which you certainly forgot the answer to. And people are likely using the same questions with the same answer o…

The solution is a government issued key pair. Probably on a Yubikey type of device. Replacing a lost one of those is then the same process as replacing a lost driver's license / passport / other government issued identification. By 2023 it's high time for these forms of identification to catch up with the digital age. It's high time to end the joke of verifying identity by birthday, SSN, "in-security questions", and…

We should just have state issues licenses with chips. At the bank I show my license; on bank website it reads the chip and pin off my license.

Re: Google Fi seemingly affected by latest T-Mobile data breach

#67

Earlier quoted context omitted.

Recently, Instagram asked to verify an account I have been using for past 2 year. Spent over $100 on ads. I felt stupid and embarassed taking my own selfie with a piece of paper with a number written on it. But then I would have lost my account, had to do it.

i used to use linkedin from a different location from my current one. i didn't think about this but when i tried to log in from my present location, it said something bullshit about "security" and now i am forced to upload my passport for verification and they pinky promise to delete the photo after verification. no fucking way

Facebook decided they wanted my drivers license to verify my account that I wanted to log in to to pull some very old pictures off of it and never think about it ever again.

You have to use the camera on a device, you can’t upload an image file (which just makes things more obnoxious, not any more secure) They tell you they’ll keep the photo stored for a year to better improve their process or whatever other bullshit. You can opt to have them only store it for one month (how nice of them) but when you do that I totally resets the flow of everything so you have to do everything all over again and it makes it seem like you’re stuck in an endless loop of doing that so you’ll just let them keep it for a year.

I caved and did it. There was no time to verify. I was just able to login.

So no, they didn’t need it for any actual verification or security reason. They just wanted the data. It’s almost funny how naked it was.

Re: Google Fi seemingly affected by latest T-Mobile data breach

#68
post #5

Not everyone got this version of the notice. Here's a reddit user who posted [1] that they were SIM swapped: > Additionally, on January 1, 2023 for about 1 hour 48 minutes, your mobile phone service was transferred from your SIM card to another SIM card. During the time of this temporary transfer, the unauthorized access could have involved the use of your phone number to send and receive phone calls and text message…

Has anyone been able to confirm that this actually happened?

Re: Google Fi seemingly affected by latest T-Mobile data breach

#69
post #49
post #21

Earlier quoted context omitted.

The why is obvious. People will lose their 2FA. It's a fact of life. Lost keys with your yubikey. Broken phone without a backup of your totp. Etc. After that, how do you prove that someone owns their account? Send a photocopy of your passport? No way to edit a picture, right? Answer some security questions, which you certainly forgot the answer to. And people are likely using the same questions with the same answer o…

In Germany there is a process called PostIdent by Deutsche Post. Any business can send you a QR code which you take to the local post office and a teller will verify your ID. The business is being notified next to instantly and you can proceed with whatever is needed. It's a nice and smooth process. Businesses could also use the German government ID, which has a chip with cryptography functionality built in.

> Businesses could also use the German government ID, which has a chip with cryptography functionality built in.

Same goes for the whole EU, it's in the new ID card standard: https://en.wikipedia.org/wiki/National_identity_cards_in_the...

I hope we start seeing some neat use cases with them. Being able to cryptographically (and in some cases anonymously) prove one's unique identity online would be pretty cool.

Re: Google Fi seemingly affected by latest T-Mobile data breach

#70

Earlier quoted context omitted.

What threat model does this help with?

Phone carrier metadata tracking for https and MITM and advertisement insertion into non-secured web pages.

> MITM and advertisement insertion into non-secured web pages.

Which for all intents and purposes don't exist anymore.

Post reply on HN