Live data from Hacker News

T-Mobile: Breach Exposed SSN/DOB of 40M+ People

krebsonsecurity.com

71–80 of 282 posts

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#71

Are there any kind of legal consequences for this in the US? Or is the reigning attitude basically 'if customers voluntarily gave the company that information, that's on them'?

Not at all. If you watched the House meeting regarding the pipeline leak, all they did was say... poor pipeline company. This totally couldn't have been your fault. You had no choice but to pay the attackers. This is because we are not getting enough funding for terrorism. It was really sickening to watch honestly. I find it funny that ransomware attackers to them are considered more like terrorists than lets say robocallers who are attacking our communication infrastructure everyday to steal money and wreak havoc.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#72
> If you’re a current T-Mobile customer, by all means change your account PIN as instructed. But regardless of which mobile provider you patronize, consider removing your phone number from as many online accounts as you can. Many online services require you to provide a phone number upon registering an account, but in many cases that number can be removed from your profile afterwards.

> Why do I suggest this? Many online services allow users to reset their passwords just by clicking a link sent via SMS, and this unfortunately widespread practice has turned mobile phone numbers into de facto identity documents. Which means losing control over your phone number thanks to an unauthorized SIM swap or mobile number port-out, divorce, job termination or financial crisis can be devastating.

Hmmm, I get why he says this, but what is the practical scenario here? We remove phone numbers from accounts after we make them? But doesn't that just mean we disable 2FA, making our accounts less secure and therefore more likely to be compromised by other means?

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#73
No, the US has far more religious fundamentalists than the EU. They believe that such a system is tantamount to taking the Mark of the Beast, quoting Revelation 13:16-17:

> And he causes all, the small and the great, and the rich and the poor, and the free men and the slaves, to be given a mark on their right hand or on their forehead, and he provides that no one will be able to buy or to sell, except the one who has the mark, either the name of the beast or the number of his name.

Additionally, politicians who pay lip service to these beliefs have an extremely strong and malleable voting bloc. It's a little crazy that a modern society is held hostage by such superstitions, but that's the way it's been. Fortunately, we just this year crossed beneath the 50% church membership threshold and the numbers continue to drop.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#74

>Can we please have this in the US? No, because a significant amount of people in the USA think any kind of federal identification system is the "mark of the beast" from the biblical book of Revelation.

Not all of the objections are due to Christian evangelism, but general public opinion against mandatory identification systems is a big reason.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#75

>Can we please have this in the US? No, because a significant amount of people in the USA think any kind of federal identification system is the "mark of the beast" from the biblical book of Revelation.

There’s no reason why the id system can’t be federated like the EU solution. Also all those hypothetical “mark of the beast” people you mention already have SSNs.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#76
post #6

As usual they don't say how this was accomplished. They call it "sophisticated" but it probably was just stupid or lazy, which is very common in most corporate hacks. Big companies don't really care much about security since it costs money and rarely causes much trouble to your stock price and exec compensation. The people who suffer are those whose data is compromised and have no idea it happened.

https://twitter.com/damienmiller/status/1427195852011937797

Copy of the tweet for preservation:

Damien Miller @damienmiller Looks like T-Mobile hasn't updated the OpenSSH installation (and thus probably neither OS) since 2014. SHA256 has been the default hostkey fingerprint since the openssh 6.8 release in 2015

Retweeted: https://twitter.com/Jeremy_Kirk/status/1427144723731402756 Jeremy Kirk @Jeremy_Kirk The person who claims to have compromised T-Mobile says the company misconfigured a gateway GPRS support node that was apparently used for testing. It was exposed to the internet. That allowed the person to eventually pivot to the LAN. Proof screenshot supplied.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#77

With the frequency of these breaches, it feels like we are moving to a post-security world where SSNs and DOBs are simply public information. Would that really be such a bad thing? Both seem completely replaceable as authentication steps.

When Social Security was introduced, the government encouraged people to get a tattoo of their SSN so they wouldn't forget it [1].

[1]: https://blog.nyhistory.org/tattoo-as-memory-prompt/

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#79

Earlier quoted context omitted.

Most European countries have some sort of strong online authentication with two factor, so it is doable.

For example?

BankID in Sweden. Sucks that it is privately owned though.

https://en.m.wikipedia.org/wiki/BankID

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#80
post #6

As usual they don't say how this was accomplished. They call it "sophisticated" but it probably was just stupid or lazy, which is very common in most corporate hacks. Big companies don't really care much about security since it costs money and rarely causes much trouble to your stock price and exec compensation. The people who suffer are those whose data is compromised and have no idea it happened.

The OpenSSH they were using was from 2014/2015 so they probably didn't update the OS or anything at all for a while
Post reply on HN