Live data from Hacker News

AT&T employees were bribed to install phone unlocking malware on company network

geekwire.com

91–100 of 157 posts

Re: AT&T employees were bribed to install phone unlocking malware on company network

#91

Earlier quoted context omitted.

Fraudulent SIM swaps are already being done and it's a lot less sophisticated than this - just show up to a store with a fake ID (or bribe the low-wage employee who isn't paid enough to give a shit so I can't really blame them).

Your SMS based 2FA is only as secure as the lowest paid employee at a cell phone store.

Lowest paid employee at the store? How about lowest paid idiot at the outsourced customer "service" centre.

Re: AT&T employees were bribed to install phone unlocking malware on company network

#92
post #79
post #27

Earlier quoted context omitted.

A contract was violated when these phones were unlocked. In return for a locked phone the buyer received a subsidy from AT&T on the cost of the hardware. I don't want people to violate contracts with me, why should I recognize someone as a hero just because I don't like the contract? To be absolutely clear, I don't like locked phones, either, so I always buy non-carrier-locked devices and it means I pay the full, uns…

Contracts are violated all the time - it's called efficient breach. Most of the time, there are no penalties either. If AT&T overcharges you, and you don't notice - they just take your money without consequence. If you can get away with efficient breach of contract, do it. As a former lawyer who write contracts all day, I will give you a virtual high five.

This comment is so good I want to create another account just so I can upvote it twice.

Re: AT&T employees were bribed to install phone unlocking malware on company network

#93

Earlier quoted context omitted.

> The contract sucks shit that's why All those people were free to buy unsubsidized phones elsewhere. They knew exactly what they were getting into when they signed up.

You give them too much credit. People don't read phone contracts and few people even know what an unlocked phone is.

And even if you can read them, most people can’t comprehend them.

And even if you can, there can be bits that aren’t enforceable and effectively void.

Re: AT&T employees were bribed to install phone unlocking malware on company network

#94

When a phone is “locked”, what does that entail? Is there a list of IMEIs somewhere that carriers check against when phones connect to their network, or is it something on the handset itself? If it’s software on the phone, surely it’s possible to hack it on the phone itself?

Handset itself. Though blacklists can exist too (depends on country and product).

For some older phones, you could download a keygen because the algo has been cracked.

But, for Apple, I understand all unlocks go through Apple HQ via the provider. Hence the need to malware the provider.

My guess is that the tech for locking is pretty good. It’s probably a prerequisite for these providers to sell your device.

Possibly with some penalty if the manufacturer can’t keep its lock robust.

Re: AT&T employees were bribed to install phone unlocking malware on company network

#95

How do you avoid charges that serious by "leaving" the company sounds like AT&T security is a bit wishy washy. I would AT&T would have wanted to make an example some of them. In the UK getting busted by the Plod / MET or the Security Service would have been preferable to the internal security.

It's possible that some executive wanted to cover it up to avoid the embarrassment of having this happen on their watch. If they press charges, the matter becomes public (both inside and outside the company). If they let the perpetrators walk, nobody finds out (or so they might have thought).

Re: AT&T employees were bribed to install phone unlocking malware on company network

#96

Earlier quoted context omitted.

Counterpoint: carriers don't always make it easy to unlock your phone even if they allow you to do so as per the contract. It can involve lots of back and forth with clueless monkeys in their customer service department. There's also the issue of legitimately buying/acquiring a phone, finding it to be locked and having no idea which carrier it is locked to nor how to go about getting it unlocked. It isn't an easy pro…

> There's also the issue of legitimately buying/acquiring a phone, finding it to be locked and having no idea which carrier it is locked to nor how to go about getting it unlocked. It isn't an easy process even if everything is legitimate and the phone was acquired legally and not stolen nor its IMEI/ESN being banned anywhere. It sounds like you're talking about buying a used phone. Sure - there's danger there. Dange…

Yes, there is danger, however it's artificially manufactured danger. There's no reason why the process should be so awful. If phone locking does need to exist (it doesn't but that's besides the point), why is there still no webpages on manufacturers' or carriers' websites allowing me to quickly check whether a phone is locked based on its IMEI and whether it can be unlocked (so whether the previous account is in good standing and the device isn't stolen)?

I remember knowingly buying a locked iPad. Even figuring out the carrier it was locked to was difficult (why isn't that displayed on the system information screen or on the error when you use a different SIM?) and Apple were of no help either. I bought it because I knew this bullshit and decided to go through it anyway but it isn't a pleasant experience and shouldn't be considered normal.

There's also the issue of recycling and e-waste. You're telling me to buy new, which is fair but what about the countless locked devices that are perfectly functional and yet stuck in limbo because nobody can figure out how to unlock them (even if they are otherwise not stolen and the previous account was in good standing)? Should we just accept that these devices are essentially bricked and can go for scrap because it's not worth the trouble to unlock them?

Re: AT&T employees were bribed to install phone unlocking malware on company network

#98
post #89

Earlier quoted context omitted.

Unlocking the phone doesn't break the contract though. AT&T is still going to charge you even if you stuff a different SIM in the phone. If you cancel your service then they'll tack on the ETF that covers the cost of the device. They wouldn't be losing money unless the guy was unlocking unactivated phones, which is an interesting legal area because technically he may never have entered into a contract with AT&T in th…

1. sign up for new phone at heavily subsidized rate in exchange for 3 yr service 2. after month 1 cancel service / credit card 3. sell unlocked phone on ebay

4. Collections agencies chase you forever over the ETF.

Re: AT&T employees were bribed to install phone unlocking malware on company network

#99
post #27
post #8

His methods were illegal but can we please recognize this guy for being an ABSOLUTE HERO for unlocking all those phones and giving the people what they wanted.

A contract was violated when these phones were unlocked. In return for a locked phone the buyer received a subsidy from AT&T on the cost of the hardware. I don't want people to violate contracts with me, why should I recognize someone as a hero just because I don't like the contract? To be absolutely clear, I don't like locked phones, either, so I always buy non-carrier-locked devices and it means I pay the full, uns…

>A contract was violated when these phones were unlocked.

Sounds like a civil matter to me.

Re: AT&T employees were bribed to install phone unlocking malware on company network

#100

When a phone is “locked”, what does that entail? Is there a list of IMEIs somewhere that carriers check against when phones connect to their network, or is it something on the handset itself? If it’s software on the phone, surely it’s possible to hack it on the phone itself?

Handset itself. Though blacklists can exist too (depends on country and product). For some older phones, you could download a keygen because the algo has been cracked. But, for Apple, I understand all unlocks go through Apple HQ via the provider. Hence the need to malware the provider. My guess is that the tech for locking is pretty good. It’s probably a prerequisite for these providers to sell your device. Possibly…

Wouldn’t it be a nice value-add if manufacturers provided an unlock after say a year or two after initial purchase? My experience with carriers is that even if you’re eligible for an unlock they’re a nightmare to get.
Post reply on HN