AT&T employees were bribed to install phone unlocking malware on company network
geekwire.com
geekwire.com
2.) How did this "deprive AT&T of the stream of payments it was owned under the customers’ service contracts and installment plans."? A phone getting unlocked doesn't void a contract, so those customers are still on the hook.
2. Presumably, it's a combination of a number of mechanisms, like judgment-proof consumers or identity thieves unlocking and reselling devices.
Recently my parents switched carriers for whatever reason, so I had to get a new phone. Honestly I would have kept my Note4 for another year, but whatever. Being a phone from, what 2014? it was well paid off at this point.
1. I went to the AT&T Store, asked them to unlock my phone. Was told, no sorry, we don't do that here. "Call the support line."
2. Called the support line, waited 20 minutes, was transferred to the correct department, waited another 20 minutes. Was told, we don't do that over the phone anymore. Go to this website here.
3. Went to the website. It asks for the number that is printed behind the battery (y'know back in my day, you could remove batteries from the devices you owned and replace them) Next, it asks for some device ID Number that you need to ask the phone for. So you turn it back on, follow the directions, etc. Then you submit the form. Then they tell you it can take up to 48 hours to get the unlock code.
4. Wait.
5. Receive absolutely no confirmation or acknowledgement that your request was received or actioned on at all.
6. Buy a new phone because it isn't worth the hassle.
Once the phone is ported to another network, the original provider is basically SOL, contract or no.
These were probably 3rd party call centers or section of the company that ran their customer service lines which gave agents the ability to unlock devices.
The amount of spin this article is using to associate locking devices to keeping customers in long-term contracts is quite strong though.
The only "free money" scenario I can think of, is stealing AT&T devices, and reselling them in the black market/ebay/etc and thus pocketing all the $$$ without having the customers signing contracts.
Ps: this is why a large company needs a large Internal Audit department.
Edit: removed an off-topic NSA-AT&T comment, added the Ps
A large number end up in collections or written off. AT&T doesn't want to issue unlock codes in those cases, because it severely reduces the chances of them getting paid.
Use this shady service to unlock without paying off the contract, and resell on the second-hand market.
If an iPhone costs $1k, maybe you paid $100 to get it out the door, then you can still make hundreds of dollars selling it.
If fraudsters are doing this in bulk (and using false/stolen identities to sign up for the contracts in the first place) then the main problem here is inadequate identity checks & fraud protections during the initial purchase and not phone unlocking.
ie. If I buy a contract iPhone from AT&T then unlock and sell on the phone, that doesn't nullify the fact that I still owe AT&T $100 a month for 24 months, regardless of where the phone is?
AT&T will usually unlock them if you request it prior to using it on their network, but would likely not unlock them in bulk for exporters.
I've purchased and used some of these when the price and timing was right and the frequencies aligned with my chosen network. It's more hassle than an unlocked phone, but sometimes the phone isn't available unlocked or locked to my chosen carrier. (More often, these phones are missing key frequencies, so not very useful on other networks)
At least if the phone is locked the carrier can just cut off service as an attempt to hopefully get payment as the phone is rendered useless without payment. However with unlocked phones theres no way for them to get the money they are owed. It's insanely expensive for them to go after each and every subcriber legally that doesnt pay.
Remember, they are loaning these devices to subscribers who cannot pay the entire cost upfront with the hope they will pay them back over the course of the contract. Unlocking the phone gets rid of the one collateral they have. Thats the reason your account must be in good standing to unlock early with every major carrier and why some do credit checks.
Case in point - bought a iPhone SE last year for $35. It's locked to TracFone.
Also a while back bought an iPhone 6s for substantially cheaper than the unlocked version from boost mobile and bought an "unlock" service on ebay.
I’ve been involved in these kinds of events in the past. The carriers go after anyone facilitating device unlocks extremely aggressively because there is a huge supply chain problem.
Consequently, just because the article says things, I’m pretty wary of trusting them to be correct.
>Fahd allegedly recruited AT&T “insiders” to install malware programs that gathered confidential information and submitted unlock requests using employee credentials via a remote server.
Sounds like the malware was stealing creds to be used to unlock the phones.
Those are just allegations, not facts.
I recently had to contact support and through chat support the person said they were adding notes to my account. Of course when I call support another day they have no record of this. They then proceed to forward my call to 2 other departments each of which has no idea why I'm calling. I talked to each of these people for several minutes.
How can a company possibly function like this?
If AT&T was your neighbourhood grocery store, they’d be crushed like a bug.
I went on vacation once, never having missed a payment to Comcast nor have we been late in the 7+ years of our account.
I get back from being gone after the week, and no internet. I call Comcast, who says there is no outage, and can send someone out to investigate in a week.
Meanwhile, I look outside, and my cable is disconnected from the utility pole, meaning someone needed a bucket truck to do this.
Going into the Comcast office, they were able to send someone out in 3 days instead of 4.
Also, Comcast has no record of them disconnecting nor can tell me why I was disconnected.
I would LOVE to ditch Comcast, but I have 0 other options in my area for speeds over 25Mb, which is a joke. I will never understand how Comcast is not a monopoly.
I guess this turned more into me hating Comcast...
Doubtful. Support staff are graded in part on how quickly they can get you off the call.
If you would like to learn a little bit more about the economics and operations of CSR call centers I can refer you to August 5 interview with Emily Guendelsberger on Sam Seder's show entitled "On the Clock: How Low-Wage Work Drives America Insane"[0] This link is timestamped to the relevant segment, but I can't isolate one phrase to demonstrate some of these operations. She employed herself in these locations to learn about how they operate, and the conditions. The TL;DR is that the outsourced companies bill on a per-minute basis, not on any actually useful metrics, in her experience.
[0] https://youtu.be/_9GGT05MAOY?t=3224
EDIT:I forgot to metion that she does discuss how poorly integrated the CSR software is, and the absurdly cumbersome user interfaces which they are forced to operate.
I suspect the support department of most companies isn't empowered to change processes, have better computer systems, etc.
Whoa there. What? Yes, he's committed a crime and should be held accountable for that. But..
Who's lives has he derailed? If I was to accept a bribe to commit a crime, nobody is derailing my life but me - to say anything else suggests a level of intelligence bordering on inability to understand and take responsibility for my actions. Can I use this defence for non bribery related crimes? How about assassin for hire?
Prosecute him for the crimes he committed and prosecute those who accepted bribes for their crimes. Theres just no reason to exaggerate like this.
Edit: And, to add, I dislike the discount / rental / lock in model the carriers use, but it does sound like crimes were committed.
The statement quoted makes it sound like people accepting bribes is entirely the fault of the person proposing the bribe. The blame is shared, nobody had their lives derailed by anyone but themselves as far as I can tell.
This person made muggings more profitable, and profited from it. If there was even one concussion from a mugging that otherwise wouldn't have happened, I would say that's a life derailed. Not provable, but likely.
No doubt the law the broken. There's no justification for that. However, the lead is the lead is the lead, and it's burried.
https://books.google.com/ngrams/graph?content=bury%20the%20l...
Personally I would never buy a carrier-locked phone, but I have the resources available to make that choice. Though the difference is maybe not huge, how many people do you think are online directly because of a carrier subsidy?
> but I have the resources available to make that choice
Usually they say something about servers and "sending your IMEI to the server" etc, and sometimes it can take a certain number of hours.
So if you left AT&T, you can only unlock two devices.
To be absolutely clear, I don't like locked phones, either, so I always buy non-carrier-locked devices and it means I pay the full, unsubsidized hardware price.
[edited to fix a typo]
All those people were free to buy unsubsidized phones elsewhere. They knew exactly what they were getting into when they signed up.
And even if you can, there can be bits that aren’t enforceable and effectively void.
There's also the issue of legitimately buying/acquiring a phone, finding it to be locked and having no idea which carrier it is locked to nor how to go about getting it unlocked. It isn't an easy process even if everything is legitimate and the phone was acquired legally and not stolen nor its IMEI/ESN being banned anywhere.
The truth is, phone unlocking is designed to be a shit-show on purpose and practices like these are just a natural consequence of that. Make unlocking straightforward and user-friendly (or just don't lock phones to begin with) and the market for these illegal things will dry up significantly.
It sounds like you're talking about buying a used phone. Sure - there's danger there. Danger which can be completely mitigated by buying at the owner's provider's store, and having an employee look up that info before giving over money.
If you want to avoid all that business, it's really, really easy to just buy from the manufacturer. If you do that, they always come unlocked, not stolen and not banned.
Broadly: locked phones suck. I would never buy one (unless it was used and on a network I'm already with). But I also know several people who cannot save money. At all. Subsidized phone plans are specifically tailored for those people. The subsidized experience will always be worse than strict ownership simply because incentives between the provider and the user are not aligned. But for those people who can't save money, I think this is the best option they have.
I remember knowingly buying a locked iPad. Even figuring out the carrier it was locked to was difficult (why isn't that displayed on the system information screen or on the error when you use a different SIM?) and Apple were of no help either. I bought it because I knew this bullshit and decided to go through it anyway but it isn't a pleasant experience and shouldn't be considered normal.
There's also the issue of recycling and e-waste. You're telling me to buy new, which is fair but what about the countless locked devices that are perfectly functional and yet stuck in limbo because nobody can figure out how to unlock them (even if they are otherwise not stolen and the previous account was in good standing)? Should we just accept that these devices are essentially bricked and can go for scrap because it's not worth the trouble to unlock them?
I've never owned a phone with a bootloader I couldn't unlock myself (unofficially or otherwise), so I don't know if this is the case or not.
It wasn't until later that I learned that cellphones could exist independent of their carrier networks and be unlocked therefrom; that one (in theory) could purchase a phone somewhere else, and then bring it to the the carrier of one's choice to be configured to interface with that network. And I only learned of that fact because I am nerd who likes to learn as much as he can about anything he becomes involved in.
Most people aren't nerds or have nerd-like tendencies. Most people simply want a magic rectangle so they can have Snapchat and Twitter in their pocket. The carriers do little to advertise the fact purchasing phones independently is even an option. So I'd say, no, most people don't know what they're getting into when they sign up.
And lest you say that said terms are right there in the contract, while true, be honest, when was the last time you carefully read and understood all 40-pages of the EULA when you have a more pressing problem to solve? I suspect even you commonly simply click the "I Agree" to get that damn boilerplate out of the way so you can Buy The Thing already.
Thanks for posting that, as I had no idea it was possible. I personally don't buy locked anymore, but last year that definitely would have saved me some trouble.
>it was made clear to me that the phone could be unlocked after a period of time. The period was shorter than the contract period.
I am with T-Mobile as well, and IIRC there are two main options for unlocking:
1. After you pay the price in full early.
2. After 18 months on a 24 months contract.
First, a subsidy can exist in many ways. It's not explicitly "when someone gives you money". It's often the case that phones are discounted through deals such as buy one get one (BOGO), for example. When you purchase those two phones they are tied to a contract that states you'll carry new lines of service through the carrier that subsidized the phones for a period of time. That's one example of a common US carrier subsidy.
Second is when costs of a phone are spread out over a contract period it is credit, not a subsidy. The carrier gives the phone to the buyer on credit since they haven't paid for it up front. This is often done now so people can buy phones they may not have the capital for up front. In this way the carrier lessens churn by locking buyers into a continuous upgrade cycle. If they want out of their contract they have to pay the balance of the phone and any early termination fees (ETFs). To imply these are "hidden installments" is disingenuous as the terms are laid out in the contract.
Not necessarily automatically.
Maybe you are referring to the FCC ruling on Verizon's request?
(I have not been following this too closely but here is what I've read)
My understanding is Verizon will (in the future) fight this ruling as well.
> "After the expiration of the 60-day period, Verizon must automatically unlock the handsets at issue here regardless of whether: (1) the customer asks for the handset to be unlocked, or (2) the handset is fully paid off. Thus, at the end of the initial 60 days, the unlocking rule will operate just as it does now, and Verizon’s customers will be able to use their unlocked handsets on other technologically compatible networks. The only exception to the rule will be that Verizon will not have to automatically unlock handsets that it determines within the 60-day period to have been purchased through fraud."
https://www.androidpolice.com/2019/06/25/fcc-says-verizon-ca...
https://www.fcc.gov/document/order-granting-verizon-partial-...
Remember, Verizon will LOCK phones that you paid for in full "to protect you".
That doesn't make it wrong. Fun fact, contracts are violated all the time, and not just between individuals and huge telecom companies, but also between large companies. If you have an issue with it you sue for breach of contract.
Violating a contract isn't a crime for a reason.
Phone unlocking itself is definitely beneficial to society and morally good. An incumbent network provider being able to leverage a small market inefficiency into indefinite bondage is not a good thing, regardless of how its justified. Never mind the e-waste and surveillance issues.
If you can get away with efficient breach of contract, do it. As a former lawyer who write contracts all day, I will give you a virtual high five.
Also I'm not sure if you're using the right terminology. From Wex, Efficient breach: A breach of contract in which the breaching party finds it cheaper to pay damages than to perform under the contract. [1]
You're not paying them when you unlock your phone out of contract so it wouldn't be efficient breach. It's just breach of contract. Also as you know it's not really breach of contract or not until a judge says so, so you can't just call contract violations that happen all the time an efficient breach.
I have a bit of legal education from years ago and I understand that there are many things that are legally "right" but there are other things to consider too.
The "unlock marketplaces" is the place where people buy and sell online and offline unlock https://www.google.com/search?q=gsm+unlock+forum
2. after month 1 cancel service / credit card
3. sell unlocked phone on ebay
Sounds like a civil matter to me.
Ignoring anything else that means they need to adopt E2E encryption for all user data (except where legally mandated to be insecure, or when the data has a fundamental need to be accessible - e.g. your bank needs to know how much money you have). Anything else, including dumbass politicians demanding magic crypto, makes your user data a valuable and achievable target.
In my case I followed your advice, thinking like a logical human, that rooting my phone could allow myself to unlock my device (which I paid retail price from their walled garden market for pre-locked devicess, no subsidy and also following years of service) but i discovered many many months after the fact that the cellular megacorp can use their OTA update service in some instances to reverse your assertion of control over your device somehow.
I used a dodgy unlock service in a time of desperation, and would later find myself locked out from my fully paid device yet again. The handset cost as much as a crappy but roadworthy car and was paid in full.
These convoluted service lock agreements do nothing at all but ensure paying customers are beholden to the capricious will of these amoral corporate entities. The marketing and lobbying makes us think this is a good deal.
EDIT: I used an opensource rooting method, and later used a dodgy unlock service which i believe this person may have been involved in reselling.
The SIM lock methods are a little bit diferent from handset to handset, but flashing LineageOS will not unlock your handset. I know there are some handsets which the SIM Lock may be manipulated via block device, but you often have to issue dialer commands to the baseband firmware.
Corrected:
> ... while he induced young workers to choose ethical conduct over corporate greed
Did he commit a crime? Yes.
Did he commit a crime against criminals? Yes.
ATT is such a horrible, rent seeking parasite on our economy, I'm rooting for whoever is redistributing that wealth. I'm not too fond of the guy, but the enemies of my enemies can be friends.
A good employer, and most are better than AT&T, has a certain level of loyalty as a defense. This bribe thing doesn't surprise me one tiny bit.
interesting that extradiction to US is ok while to mainland China - isnt. Speaks volumes about whom HK people trusts more, and it doesn't look very promising wrt. peaceful and harmonious full integration of HK.
Wrt. the original post - impressive that AT&T couldnt notice what was happening at that scale for that long. Somebody need to sell them one more audit software package.
How was Edward Snowden allowed to chill in Hong Kong? Was it because the indictment/extradition request was political and they don't honor those on our behalf? I thought HK just ignored US arrest warrants.
I've been switching to hardware keys when I'm able but it's not always feasible. I just bought a Titan key combo and you can't use most 3rd party email clients with it so that made it kind of useless to me (since Gmail's mail app isn't that great)
What? Whose lives? Those of the executives who got a couple thousand dollars less on their multi million boni packages?
Don't get me wrong, bribing people to install malware is reprehensible, but that argument is just... unbelievably braindead.
I would AT&T would have wanted to make an example some of them.
In the UK getting busted by the Plod / MET or the Security Service would have been preferable to the internal security.
For some older phones, you could download a keygen because the algo has been cracked.
But, for Apple, I understand all unlocks go through Apple HQ via the provider. Hence the need to malware the provider.
My guess is that the tech for locking is pretty good. It’s probably a prerequisite for these providers to sell your device.
Possibly with some penalty if the manufacturer can’t keep its lock robust.
For example mikeselectricstuff (hackaday readers will immediately recognize the name https://www.youtube.com/user/mikeselectricstuff/videos , he is known among other things for Reverse Engineering the iPod Nano 6 screen and hacking FLIR E4 Thermal Imaging Camera to full resolution) has been making a living cracking GSM handset firmware in the nineties.
Quite a while ago I was on an AT&T family plan with my aforementioned family. An unexpected death in my family caused a falling out/estrangement situation which jeopardized our cellular service, along the lines of an intestate inheritance, forfeited property, decades of fraud/extortion...and my borderline personality mother becoming enraged at the fact that we would now be reassessing my family's troubled history in the wake of this tragedy. The result of these events were that my (quite old) AT&T smartphone service was unexpecgedly cancelled, leaving me out in the cold. I needed service fast, and got a sim card ASAP but I did not reckon that my (fully paid for) cellular device would be carrier locked.
This is my mistake of course, but the result is that I was, late at night, caught out with no functional device to use with my sim card, and a brand new MVNO service agreement. I took to the internet in order to find a solution, and ended up using my privacy.com account to pay for a rather sketchy Samsung unlock service, which worked like a charm.
Eager to forget this entire affair, I moved on with my life.
One day about a month or two ago, my Samsung handset began demanding a carrier unlock code. Confused, and in need of service, I shelled out for the nearest used smartphone thing I could find.
This was rather alarming as I was cut off, yet again, and until this day I had no idea how my handset had relocked itsself! my MVNO CSR couldn't help, bless his/her soul, insisting I would need to contact the carrier for the unlock code. Instead, I hit that thing with a hammer and called it a night.
After I used the dodgy unlock software which I paid a 20 for, I had monitored my handset for malicious activity via my personal security gateway but could never identify anything unusually malicious.
Now I have a backup plan, and carry a spare flip phone.
If your mother has access to lexisnexis, I might consider a restraining order if your situation sounds familiar.
I concluded that AT&T has rescinded these unlock codes, leaving untold numbers of legitimate users without a way to conduct business.
Carrier locked devices should be outlawed. AT&T appears to my naive eyes as a malevolent shitshow, much like verizon and comcast and other rent seeking walled garden extortionists. The history of these telephone companies precedes them, but gosh i wish that my real life didn't feel like it existed in Eve Online.