T-Mobile says investigating data breach involving 37M accounts
reuters.com
reuters.com
> "some basic customer information was obtained, such as name, billing address, email and phone number"
Yup definitely no sensitive data there
Comparing apples and oranges.
Already had to freeze my credit reports because of last time, this new breach is ridiculous.
It's all just a big compliance and cost x benefit balance act. We won't get any real security at scale until damages actually hurt insurers enough that they actually invest in understanding and mitigating the problems.
Over the last 24 months, I have seen some weird increasing rate of vulnerable API endpoints in my own research. One of which would allow a bad actor direct access to over $2BB in funds (from a major organization worth more than $10BB), another plain-text credit card numbers and billing addresses (same application as the first); another were more plain-text credit card numbers (much smaller org, but still sizable). Both attacks were alarmingly non-trivial and would be scored as critical.
Why this trend is seemingly increasing, I don't know.
> However, some basic customer information was obtained, such as name, billing address, email and phone number, T-Mobile said.
This isn't even the first time they got breached and yet it has happened again. They have not learned anything.
I think it is time that we stop using phone numbers as a login mechanism. It has always been a completely stupid idea from the beginning of its use.
Let the SIM swapping attacks and identity theft games begin.
Why do companies always try to sugarcoat things? Its analogous to doctor gives us bad news but shows us the silver-lining. I guess these are more of the PR side of things.
> However, some basic customer information was obtained, such as name, billing address, email and phone number, T-Mobile said.
Is this not sensitive information? That all qualifies as PII.
[0] https://www.cnn.com/2023/01/19/tech/tmobile-hack/index.html
This would include things like race, health conditions, disabilities, sexual orientation, political views - basically things that you wouldn't expect T-Mobile to be storing.
I hate that this information is out there. For most of us it’s one in a series of unwanted disclosures. I care and disapprove on principle but I don’t think I’m compromised any more than I already am.
Not after T-Mobile breach.
Also, this type of PII got leaked very often by now.
https://www.sec.gov/Archives/edgar/data/1283699/000119312523...
"some basic customer information was obtained, such as name, billing address"
Yeah THIS is why I vehemently disagree with KYC laws, especially those requiring a street address. I shouldn't have to tell someone where I sleep to use their business.
Breaches like this enable stalkers, thieves, domestic violence, lots of bad things.
That should fix the problem.
This is far too regular an occurrence for T-Mobile. I have never been a customer of theirs and so far as I know my info has never leaked from my cell provider. Unfortunately I was caught up in more than one other major data breach over the last 10 years so it is all out there but still, when one company has this many similar breaches it starts to look like planned events.
I don't trust any message from anyone not in my address book. Even then, sender can be spoofed, but it's less likely.
In the past I told her to ignore every text message no matter how urgent or convincing it looks. Fortunately, she can't figure out how to read old messages so once a message times out and disappears from the screen she won't see it again.
Credit monitoring always seemed to me like a scam ala antivirus, but in all fairness I have never purchased it either.
Most of that used to be published in print and sent out to everyone. Do they still make phoneboks?
This issue is my "abortion" issue. What I mean is, I don't care who the candidate is, how immoral or unlikable they are. If they run punishing companies for data leaks, I will vote for them instantly.
The root issue is that we are complacently pretending that any entity is capable of ensuring long-term security of a million-datapoint database of valuable information while at the same time thousands of their employees are allowed to work with it.
My old boss was working in this space a decade ago. Private data brokers you control, that companies would have to ask for info, pending your approval and such. As you might imagine in the era of sell everything you can, the idea never took off.
In a broker scenario, the company would access it as and when needed, on a permission basis. The cool thing about such a model is that if and when you move, change phone numbers, employment, etc, you'd only have to update it in one place! The last time I moved, I think I had to change it in about 20 places. Why does every company need to independently save my address?
Companies are just ideas that exist to help society run more smoothly, if one racks up enough penalties that it goes under, that’s good enough proof that it isn’t doing its job.
It should REALLY hurt. Like strong financial penalties and CEO going to jail-hurt or at least board of directors throwing the CEO on the pavement-hurt.
For now, it's just a potential slap-on-the-wrist cost of doing business which companies like T-Mobile or Google are very happy to risk time and again.
So, a CEO runs a company which uses another company to host their servers which uses an operating system built by another company, and runs on hardware built by yet another company and has a processor built by another company yet again.
Every one of those is a potential security hole. Now who do you want to send to jail again?
I get it, it’s frustrating. But the reason we haven’t solved this problem is because it’s both complicated and complex.
People responsible for making decisions - usually holding a title of CxO. Judges are not unreasonable - if a CEO is responsible for cutting corners on security spending, it's something different than a faulty hardware (say, intel CPUs) which "everyone" uses.
Mostly we call those trade offs, with this huge gray area where we argue about whether something is a trade off or unreasonably cutting corners.
Again, these are difficult problems to address. The social aspect of getting humans to agree on something like this is hard.
For example, financial companies are required to get reams of highly sensitive data to do KYC checks. The thing is, most companies would greatly prefer NOT to have to access and store this data, but they are legally required to. As a data point, when Stripe came out with their Stripe Identity product, many were surprised that, unlike their credit card processing where a merchant never gets to see any card data, with Stripe Identity the full image of highly sensitive data like drivers' licenses and passports are available to the Stripe clients. But the reason for this is that KYC rules require this data to be available to financial institutions. See top comment on https://news.ycombinator.com/item?id=27502993 and Patrick Collison's response.
IMO the only way this problem will ever be solvable is with some sort of broad-based tokenization solution. It's just impossible for most large companies to keep this data secure forever.
The real problem is that the data is considered sensitive in the first place. It's essentially publicly available data at this point and entities that want to extend credit to a particular individual should not be able to solely rely on that data to extend credit.
The law needs to be changed to allow an individual to sue creditors and credit bureaus for libel when they accuse them of failing to pay or defaulting on a line of credit.
https://www.cnn.com/2021/02/26/politics/solarwinds123-passwo...
But serious security could hamper business growth and in the end shareholder value - not security nor morality - counts.
In a capitalist world information security lapses is just the cost of doing business.
BTW, if you were in the previous breach, the deadline for making a claim under the class action settlement is in 4 days (January 23, 2023):
https://www.t-mobilesettlement.com/
You get $25 or actual damages with documentation. (Californians get $100 instead of $25 because of some law.)
As part of this settlement, T-Mobile is also agreeing to spend an extra $150 million on information security during 2022 and 2023. I guess that money didn't get spent yet or it didn't work. (See section 5 in the actual agreement at https://www.t-mobilesettlement.com/home/1552/DocumentHandler...)
Well, some consultants are getting paid. Not so much the people who were actually harmed.
> Imagine a world where all software is written using formal methods
(emphasis mine)
I would be much more agreeable to enforcing higher quality for more important things, including ex. systems that store PII for large numbers of people.
And they were still breached. "gross negligence" definitely comes to mind.
Now we have strict building codes and thousands of buildings with dozens upon dozens of floors that can resist hurricanes and earthquakes.
Software development is barely 3 generations old. One day we will have sound engineering and fairly solid systems on a scale we can't even fathom today. But it will take a lot of collective learning. For now rickety systems can hoover enough value for their owners that they are still getting built all over the place.
Furthermore, to prevent government scope creep, can we say the $10,000 comes from the dynastic wealth of whatever congress critters backed whatever bills required the companies to collect the stolen data in the first place?
There is no reason for the cell company to even know who its customers are, beyond dealing with sim card replacements. That could be handled without requiring PII.
Yes, exactly. It's indeed a massive value that's been stolen from the customers.
Individuals should not have to spend time proving they did not borrow money, lenders should be liable for any losses if they want to save money and extend credit with just a SSN/name/address verification.