Hackers claim they breached T-Mobile more than 100 times in 2022
krebsonsecurity.com
krebsonsecurity.com
- My Gmail account was compromised
- My Amazon account was compromised
In Gmail, they added a filter to hide any shipping or customer service messages from Amazon.
In Amazon, every other day, they placed an order for a ~500 USD GoPro device, delivered to an address in NYC. This address changed with every order.
Both passwords to both accounts were kept the same.
After I caught on to the above once I received my credit card statement, in November:
- They attempted to purchase something with my credit card. Security mechanisms triggered, and a verification code was sent to my phone at 4am in the morning. They successfully validated and placed the order. My credit card company assures me they input the right verification code.
- They applied for an Amazon credit card using my identity. It was auto approved, and they used the credit card to purchase ~5k worth of items.
I moved everything off of that T-Mobile number, and switched over to GoogleFi (only to learn GoogleFi uses T-Mobile also... still better than T-Mobile directly I'm hoping).
Edit:
I also wiped my phone, eventually thought that wasn't far enough, and switched to a new device entirely. I'm still unsure how the above occurred, because some of it feels beyond the scope of a SIM-swap.
And while on the topic of banks, most will suspend access to your online portal if you log in with a VPN. Give me a bank that allows VoIP phone numbers, VPN access, and TOTP and/or FIDO support for 2FA and I'll ditch Schwab right now.
They both use Symantec VIP but it’s fairly easy (for developers at least) to export those tokens and import them into something like Authy, Google Authenticator etc.
I know that Vanguard, for instance, supports non-SMS 2FA but doesn't let you disable SMS as a fallback (and I'd rather not just totally remove all phone numbers, but maybe I have to...).
Maybe they've changed their policy since then. But when you call to get set up on a new device, how do they verify your identity now if you don't have SMS fallback?
Any idea how G and A were compromised, password reuse?
I used to work tech support for cell phone providers, and while we were trained about fraud, the nature of the industry low wages, high turnover, makes this a security flaw that financial institutions should not risk.
But if the attacker already has your info, then couldn't they just add another line to your mobile plan, so your handset continues working, just with a new, unbeknownst to you phone number? That way it wouldn't be noticable on the handset.
The real question is how long do you think it would take you to break into your own Gmail account after the passwords been changed and the attached phone numbers also been changed?
Probably longer than it would take an attacker to drain bank accounts, I figure.
Or, you know, they can just bribe the store employees. Has happened before, still happens, will keep happening as long as a phone number is considered important for anything at all.
Moreover, you don't want it to be tied to your identity. The fact that anyone can pretend to be you and hijack your phone number is exactly what makes it insecure.
A stolen phone can of course be a problem as well, but at least it's somewhat under my control and I may notice pretty quickly when it's gone.
I initially thought only Amazon was compromised. I thought it was due to us throwing away a FireTV device (assumption: we didn't log out and de-register) that was then used to order items.
And then I found they added filters to my Gmail account to hide the Amazon orders, and went into full panic mode.
Edit: I can't actually find a help article, but it's under "Try another way to sign-in" and they'll text you a verification code to your registered account phone number.
Does anyone know if Authy uses SMS for any kind of recovery? I don’t see an option in the security settings
https://support.authy.com/hc/en-us/articles/360012427914-Is-...
I’ll agree though that Authy’s docs are really ambiguous about account recovery.
I wonder then what the point is of having 2FA at all if you can just click a few buttons to bypass them with an SMS.
Were you specifically targeted in any way that would make the attackers go find your phone number and perform the swap?
So you didn't have one lol. I understand that's an extremely frustrating situation though. Part of making backups is testing them once in a while (at least making sure they exist). Something else you could've done previously was to use Authy or Aegis which helps you backup the seeds themselves encrypted under a passphrase so you can recover the accounts even if you lose everything else. Although of course, all of this depends on your threat model, if you don't care about SIM swaps or if losing the account is still much more worrying then I guess it's just a unnecessary hassle/risk.
How do you know T-Mobile was the entry point, and not say, Google (e.g., Google Chrome, Google Ads)? What type of phone did you have (e.g., Android or iPhone)? What is your browser and Search Engine on your smartphone?
Thanks!
I used an iPhone, Safari mobile, Google search engine.
Did you happen to report to Apple and Google (for documentation)?
We need more robust security integration to catch things before they are pushed to results. I understand latency will increase, and some ads revenue will decrease. But like, isn't it also cool to have a customer base that is better protected against egregious attacks, attacks that could be prevented? IMO, yes. It's called "stewardship."
It’s hardly a second factor if it can be used to entirely replace the primary one.
https://support.google.com/accounts/answer/183723?hl=en&co=G...
I think years ago I found my number there with no-recollection of every agreeing to it and quickly yeeted it. (You can remove the number but keep recovery email)
You can also enable Advanced Protection[1] for your Google account, but other repeat offenders like Github will continue to allow SMS fallback to bypass 2FA if you have a phone number listed anywhere.
I gotta admit, that's pretty clever. Crude, but effective.
Our group is small enough that I get very few alerts at all, and I've caught two compromises that way.
Of course I only found this out after being burned by it. Turns out they’d sent me a message telling me the item I returned was not in the same condition it was sent in (it was), but the message was utterly lost in the flood of ‘order received/sent/delivered’ mails they send (with the same subject).
What your experienced can't be done with just a sim swap attack, as you would have lost access to your phone number. And it can't be done with the described T-Mobile hack, as it would have given the hackers silent access to your texts, so they could have reset your Gmail password, but then you would have noticed a password change (and you claim it didn't change.)
There are lists floating around with 10s of thousands, or hundreds of thousands of users with known passwords in Google, Amazon, Paypal, Coinbase, etc.
Episode 112 of Darknet Diaries (March last year) has a really good breakdown of these markets: https://darknetdiaries.com/episode/112/
Sounds like an easy way to burn your exploit after using it a few times to get electronics off Amazon.
I’ve heard multiple independent stories from a few friends in Law Enforcement about cases involving trafficking of large quantities of stolen GoPros (obtained via methods not unlike what happened to you).
Interesting you mention NYC - at least one of these cases involved a very high volume fencing syndicate operating as a legitimate storefront in NYC - with merchandise fraudulently obtained from Amazon[0]. A friend of mine worked this case.
Small, fairly high value, high demand, and no remote shutdown/disable/reporting - somewhat of a perfect storm I suppose.
[0] - https://www.cnbc.com/amp/2018/06/07/how-the-finans-stole-1-p...
They'll have all the original packaging and put it up as a "pre-owned" unit, but then you open the listing and they have 20 of them for sale.
We also had a local hotel/waterpark that was running a burglary/fencing operation in the mid aughts. The room cleaners would look for gopros, iphones and other electronics. If they found anything, they'd take it and hand it over to the two managers, who then fenced it out to local guys who'd either pawn them or sell it on Craigslist and they'd split the money.
Customers routinely complained to the managers who were the fences so they'd tell the customer they'd fill out a complaint form and send in a police report to the local PD. Obviously, that never happened. This went on for about two years until people on social media and review sites like Yelp started discovering what was happening was not an accident. They finally busted the ring and within a few weeks, the waterpark and hotel were shut down for various other repeated OSHA and other infractions that went unfixed. The local paper reported even though they busted the ring, the money and the goods were long gone, leaving the victims with little recourse.
If you're the victim of a crime, you should do the police report yourself - also for things like insurance claims.
Not always.
> “These breaches should not happen,” Weaver said. “Because T-Mobile should have long ago issued all employees security keys and switched to security keys for the second factor. And because security keys provably block this style of attack.”
At what point do we consider industry self-regulation on this a total failure? You don't need to make Yubikeys a part of every auth workflow in your corporate enterprise if there are legacy systems/integrations, but you should at least do it for the things that can change customer mobile subscription details and there can't be any excuse.
I see no reason to assume that premise to be correct in practice. It's not like the US Government hasn't been breached countless times or had Supreme Court opinions leaked; and it's not like corporations that really tried and should be examples of best practice haven't also been breached. Also, what law can prevent insider attacks? There's already plenty of laws making that illegal.
There's no law that just "makes security happen" - and, actually, I would be fundamentally opposed to such a law because it turns security into a simple matter of compliance. "We're SCA compliant, therefore we're good!" And technology changes way too much - a security law that was written 10 years ago would be a disaster today. See South Korea's Banking Security laws for an example - they basically enshrined ActiveX in their law with roll-your-own-crypto to this day. And we know now that was a trash idea but nobody wants to take the blame for upsetting the security standards. https://palant.info/2023/01/02/south-koreas-online-security-... and https://www.nytimes.com/2022/07/08/business/korea-internet-e...
There is obvious, direct, and destructive customer impact here.
Edit: actually I know people working in security roles for T-Mobile, and I am sure they or their sister teams are trying.
Seriously though, so long as cybersecurity insurance and "industry best practices checkbox management" is easier and/or cheaper than actual meaningful security measures, it will never be solved.
Worse, when a meaningful security measure that could actually make a difference collides with something in a best practices document, you know who will lose.
I'm not cynical at this point, no...
Just the way boards of companies have fiduciary duty, there should be some of sort customer information protection duty that companies are responsible / liable for. basic security practices are being neglected at far too many companies.
In another thread I proposed making white-hat hacking legally protected, even without permission from the company. If your system is constantly being tested by mostly white-hat hackers seeking their next responsible disclosure and bounty, then that's something.
Bug bounties already exist, but they're opt-in, and companies that need them the most are not opting-in. We also see the people who do things like press F12 get legally bullied[0].
Changing the laws to protect white-hats and responsible disclosure would help. This would be a law that "just makes security happen".
[0]: https://www.youtube.com/watch?v=lSsvzBV0tyI or https://arstechnica.com/tech-policy/2021/10/missouri-gov-cal...
Certainly a risk of this proposal is that some black-hats would get away, but that is already happening, so it's not really a problem of this proposal. This law wont affect black-hats because they already operate outside the law.
The problem is nobody can investigate the security of a company without facing major legal risks. As I linked above, a researcher pressed F12 and next thing he knew the Governor was threatening to prosecute him, and that's just one example. I believe it is a felony if I want to investigate for myself how secure T-Mobile's systems are, because they have not explicitly invited me to do so.
About 10 years ago I was doing some web scraping and came across a website that was exposing PPI (SSNs and more) of thousands of people. It was in an API JSON response, the JavaScript only displayed part of the data though. I just closed the site and never touched it again. I'm not a security researcher, I don't know how to safely report what I saw. It all seems personally risky for little personal gain. So I closed the site and let it go. My attitude has long been that if society wants to offer me some strong legal protections then I'll do the right thing, otherwise, society can burn. Half the nation's personal data can get stolen twice a month, as is already the case. When society cares enough to do something about it maybe I'll change my attitude.
> I would be fundamentally opposed to such a law because it turns security into a simple matter of compliance.
True, but that's better than effectively having no security at all.
And regulation takes a while to create and put into practice and with the rate things are going, by the time regulation has been out in place, the current best practices will have changed.
Whereas writing regulation on building bridges is easy because the timescale of us building bridges spans literal millenniums.
I'm not saying I expected self-regulation to work. But, if you are in a position of customers seeing direct harm every day, it's not unreasonable to ask why there is a failure here.
Even your average developer isn’t going to be aware of security changes in the industry to know what’s important or not. It’s going to be even less likely they someone not in engineering to remotely know what’s important or not.
Security professionals know but do you seek out a cardiologist first before you ask your GP? Probably not because, being not at all trained, you have no clue about anything. And if your GP doesn’t know, you are kind of on your own.
If you’re trying to decide between electricians but you know nothing about electrical jobs, you’re going to be unable to make any meaningful decision. You’re just going to pick the one that sounds the best.
Heck, you could be using the same mediocre electrician for years and even recommend it to friends because you still have no clue about the workmanship.
Self-regulation has failed because the cost of a data breach remains relatively low compared to implementing security measures, at least on the surface.
Maybe, had you said three decades? But not two. It was already mature by then.
Two decades ago was 2003. Even consumer banking was online, and in many countries exclusively 2FA.
I've worked the banking space then and we absolutely had smart cards. Military and defense had them everywhere. Proprietary solutions had already gone away replaced by PC/SC. NT 4.0SP6 had support out of the box, because it was already a hard requirement for many customers two and a half decade ago.
But outside of government, defense and banking, who exactly was using it?
It was not on the radar of the vast majority of people. Most technology takes decades to filter through the world
But it was absolutely a standard form of authentication already, and regarded as best practice security for those who cared about such things.
Which perhaps weren't that many, but then again, still isn't.
https://www.faa.gov/newsroom/out-front-airline-safety-two-de...
I think financial penalties are still the best bet if they are large enough to really hit profitability but not large enough to kill the company.
Look - too big to fail means we let too many companies merge. This isn't a healthy situation that losing T-Mobile means having no competition left. We should probably unwind some mergers first.
It also doesn't help that the US government is a barely-functioning kleptocracy. They're more concerned with passing legislation about transgender boogymen while they line their pockets than they are about ... well, anything else.
Bigcorp networks are emergent, not pieced together. Threat actors just need one or two flaws. Case in point, the mac and yubikey corp with big fat wallet that was hacked: uber.
Everyone is a backseat driver with silverbullet solutions, meanwhile there are decades of research and best practices solve all these problems.
People who chase absolute securitu through one size fits all solutions do more harm than good.
You have many many best practices, have a good email protection service/sandbox-detonation, MFA, detection+monitoring after the fact, CAP so threat actors can't just login from any random IP or device, threat hunting, user training,etc... these are all things a good security program should be doing to create the most hostile environment for a threat actor.
People had the same frustrating MFA argument on HN with Uber when it was hacked but long after the news story hype died down it was revealed that the TA got a contractors' creds via infostealer malware. Access to corporate networks is a common trade item in certain forums.
In this case mfa of any kind, cap and url-rewriting email security service are all layers of defense that could have caught this before impact.
imo you should always have at least two 2fa hids in case one gets damaged or lost or whatever and you need to force log yourself out or something.
In those cases, hardware keys for employees would not help.
I suspect that the employees aren't merely doing a sim swap attack with their work login credentials. Like you say, they'd clearly get fired/prosecuted for that.
Instead, I suspect criminal X buys a nice thing delivered to employee Y's house. Then, criminal X phones the helpdesk repeatedly till they get connected to employee Y during working hours. Then, they claim to own the phone number of victim Z, but have lost the phone, their id and everything else. But they manage to tell employee Y the answer to two of the secret questions "What is your gender", and "Did you use the internet in the last month?". The employee uses this, together with their judgement to proceed, according to company policy, and issue a new eSIM.
Later, when anyone finds out, the call is listened to, and the employee can legitimately say they were just following policy.
Want to cancel 20 numbers that still got 2 years until the contracts expire? Sure, let me do that for you. Want to change sim? Sure, just give me the new sim number. Want to add 5 tariffs to your plan? Sure, do you want phones with that?
That was 6 years ago but I still got friends I talk to there, and not much has changed.
They just walk in to the store, steal a tablet out of the manager's hands, run away with it, and make all the changes they can with the logged-in session until corporate locks out the device.
I guess a second factor confirmation on every modifying request would solve the issue?
I was kind of amazed and shocked at the same time how there already seems to be an established sim-swap-as-a-service economy with specialized roles and plenty demand to warrant expansion...
So T-Mobile offered you a "quick job" that immediately gave you access to their inner sanctum?
These threads are a hoot.
People say dev salaries are way too high but this is basically what internal systems look like at all the places that refuse to pay fair market value.
I think something more accurate is
> TMobile getting hacked is a 'how many times', not a when
But adjust further...
> All cell providers getting hacked is a 'how many times', not a 'which'
That's one way to reduce headhunting spam.
While I use a yubikey, OTP (where possible), and unique passwords…there’s still places where I have no choice and my number is my auth (or stupidly a reset option).
I genuinely am happy with TMO service in the US, and frankly abroad it’s excellent…but I’d be lying if every single article I see about their security breaches reminds me I may be on borrowed time myself.
Even if you use ATT or Verizon, the article mentions they're also hacked and SMS intercepted often.
Verizon and AT&T are the other of the big 3 carriers in the US, and they're not reselling T-Mobile. And all 3 have MNVOs (mobile virtual network operator) that resell and/or combine the networks of the big 3.
The issue is for T-Mobile direct customers, which obviously their internal systems have access to. I see no reason why T-Mobile would have access to users accounts at another company…
"Google says that hackers may have accessed limited customer information via the compromised system, which includes phone numbers, SIM card serial numbers, account status, and mobile service plan data. The system did not contain personal customer information such as names, email addresses, payment card data, government IDs, passwords, or pin numbers."
It's something, but not perfect.
MVNOs do not roam on the carrier, however. The MVNO has a close direct relationship for wholesale access to the network. Roaming is a wholly separate method of access.
Of course you'll still be affected by SIM-swapping etc that just change how your number itself is routed.
And all of them have supposedly been compromised, but T-Mobile is the most compromised.
> While it is true that each of these cybercriminal actors periodically offer SIM-swapping services for other mobile phone providers — including AT&T, Verizon and smaller carriers — those solicitations appear far less frequently in these group chats than T-Mobile swap offers. And when those offers do materialize, they are considerably more expensive.
So the choice is, which one is the least compromised, unfortunately
1. https://en.wikipedia.org/wiki/List_of_United_States_wireless...
technically there are a bunch other small carriers that run their own equipment (not resellers), more than I thought there were: https://en.wikipedia.org/wiki/List_of_United_States_wireless...
https://www.theverge.com/2023/2/28/23617347/dish-cybersecuri...
The weak link is usually retail or channel. TMobile is in a high growth phase, so I’d hazard to guess they are more disorganized. Switching to Verizon may reduce exposure, but they have their own similar issues - an aggressively dumb carrier employee is capable of almost anything.
All this to say, I trust ATT and Verizon slightly more than T-Mobile
Just like how the locks we buy for our exterior doors are really weak but that’s currently fine for the status quo. You’re not going to preemptively spend money to upgrade your locks.
This is true of just about every single mobile carrier today. In fact this is true of all telecom companies for most of their history from mobile carriers, to cable companies to ISPs. The entire telecom industry is an unending series of consolidation and acquisition of assets. This is already 12 years out of date but this should give you an idea:
The field of competition is very limited, and most consumers I'd guess are either unaware of these problems, feel helpless about them, or don't understand their significance. So what's the pressure exerted on T-Mobile to invest in this problem? There's very little.
Unfortunately, for a system with such a big footprint and given the complexity, you'd need a huge amount of pressure to have a meaningful impact on the problem.
In the opinion of HN is this the most secure way to do it while still allowing me to use services that force SMS based 2FA (almost everything) ?
Is there a better way?
I think totp would probably get more traction with normal users if people started calling it app verification, or something similar eventhough that is slightly incorrect.
>Nixon said SIM-swapping groups often advertise low-level jobs on places like Roblox and Minecraft, online games that are extremely popular with young adolescent males.
>… “They recruit children because they’re naive, you can get more out of them, and they have legal protections that other people over 18 don’t have.”
If they are doing all this through phishing and aren't being as successful with other networks there's some serious issue that's being overlooked. It's unclear from the article if this is due to training, lax security on internal tools, lack of two factor (as claimed in the article) or something else (even insiders).
That's too bad, I've been on T-Mobile for years. Whenever I can I'll use yubikeys or OTP. But there's still a large number of sites and services that rely on SMS.
I avoid using my actual phone number whenever possible and use a Google Voice number. Hacking Google Voice would require hacking my actual Google account instead of just tricking someone at the phone company.
Are you saying the Google Voice phone number lock is useless and that any carrier can just steal Google Voice numbers regardless of the lock status?
https://old.reddit.com/r/GoogleFi/comments/10pjtie/google_fi...
I don't work at Google and don't know if this is possible with Google Voice. However, Google Fi is their paid service, so I would assume that's the one they'd want to protect the most.
There arent any SIM cards to be hijacked with Voice because it don't provide cell service.
And as an added bonus, I can automatically send all incoming google voice calls to voicemail and not have to worry about missing a family emergency. If I get a phone call on my actual cell number, it's almost guaranteed to be someone I know closely.
I do too. Sadly there are a number of sites/orgs that require you to use a mobile number. I don't really understand why.
A few years ago I had to regain control of an account that I had lost the credentials for. No problem, Tmo support just needed me to provide one of the last 5 phone numbers dialed. So yes, there are some serious issues overlooked.
We've always known that sim swap attacks weren't hard. But I've largely understood them to be not scalable. You can sim swap almost anybody by calling Verizon on the phone. But you needed to call them. This, in my mind, largely meant that the risk of sim swap for most people was pretty low - certainly far lower than the risk of phishing.
With this method, it scales. Pwn one person who has relevant system access and then you can sim swap as many people as you want. Now there really is a meaningful difference in security posture between sms and otp.
That’s the banks’ choice though. Are cellular providers selling them a secure authentication service? Or just an insecure best effort message delivery channel?
But then of course the banks can ping that liability further upstream: as a customer, when you choose to opt in to SMS authentication, you’re the one vouching for the security of your cellphone provider, telling your bank ‘I trust their account security enough that if you send a message to this number you can assume the recipient is me’
So now you’re left going to your cell company and saying ‘since the bank said I could use you for auth, you’re properly secure right?’
And their answer is ‘lol no. check our t’s and c’s.’
And then you wind up saying ‘but I want to be able to assume that and I think my cell company should be liable if they aren’t’, and asking for the cellphone company to be regulated like a bank.
Because banks are that good at deflecting liability.
Even voice communication must be encrypted when cell-to-cell so that Joe-Blow-Nobody and the President of the United States have exactly the same protection on their personal cell phones. If a company key use used for lawful intercept there must be a massive audit trail that makes it crystal clear who monitored what and for how long. No more pressuring people like me to give authorities unfettered and un-monitored lawful monitoring access.
That may also raise prices massively. I prefer that mobile carriers get dumber (collect less info) and less regulated, not smarter and more regulated.
If your business relies on SMS for authentication, you are liable for all the fallout of using an insecure channel.
It's the bank's job to secure your funds, not a mobile carrier's. Let's keep it that way and make it more clear to consumers and businesses.
I had no idea this kind of attack was possible and I don't know how it works or whether it was related to the T-Mobile breach. Had the hackers attempted an account takeover using the information they collected from me they could conceivably have stolen all of my savings.
The article seems to be US-centric, so, only T-Mobile US? Or all 13 Deutsche Telekom subsidiaries [1]?
What about T-Mobile Netherlands, which was sold off by Deutsche Telekom but retains the T-Mobile name?
We get it, no need to repeat yourself. ;-)
Caller ID services and Iphone Provisioning.
Its way worse than the media/public even knows. Its networks built on networks, with api's everywhere.
Also, TMO allows you to enable 2FA but ignores it when enabled, still allows you to sign on with email/pass.
my friend had google fi and was caught in this, among other things they had their instagram taken over. scary few days. thankfully their roommate works at meta...
I think the only way to be really safe is to use one of the smaller MVNOs and never ever ever reveal who your carrier is
But that's ~$20/mo and a moderate annoyance, so for now mostly just fingers crossed that eventually everywhere that matters will allow me to switch fully to authentication apps and hardware keys.
A separate number for each account might help. Maybe.
$2.50/month, RedPocket annual eBay plan.
wonder if that works...
Even if you do use physical keys, malware on the machine from a phishing+0-day attack can simply wait for the user to log in with their physical key, and use an existing, valid session to inject an attack. This has existed for at least 15 years since I first saw the attack, and it still works great, even with FIDO2.
What happens to T-Mobile if an attacker takes over an account, regardless of security method compromised? Basically nothing. Yeah, some customers get sim-swapped, who cares? T-Mobile has not lost any money. So there is no incentive for T-Mobile to have better security in those cases. Hence, no need for physical keys, which wouldn't stop all attacks anyway.
It's hard to find people with languages and tech skills so most outsourcers just fulfill the former and cover the latter with endless infernal flowcharts. Really sucks when your problem is not on the chart. Escalating is usually discouraged by giving targets per day to the agents.
I guess you're in the US so perhaps language isn't as much of an issue but a lot of US companies support from the Philippines now because they have a favourably perceived accent (unlike Indians which a lot of customers have come to associate with 'poor support' so it leads to kneejerk reactions *). But anyway in the Philippines it's now hard to find staff too.
But anyway my point is that the support experience is not really related to internal IT competence.
*) not my personal opinion but I have seen US companies in particular use this argument. Unlike in the UK where Indian accents are common. I worked on the contact center tech realm for 20 years.
My hot take is to make many forms of hacking legal so long as the hacker reports their findings to the government. Let's have a free for all where every white hat and grey hat hacker gets to test the security of all companies, no permission from the companies required. Otherwise, it's only black hats that get to do the hacking, and they won't tell anyone when the find a vulnerability.
Everyone wins except for the companies who will be embarrassed they can't build a secure system to save their life. And they won't be able to legally bully someone for pressing F12 anymore.
This is important, it's a national security issue. Extreme measures like this are justified.
Some hacks, such as DDoS attacks might have to remain illegal. But otherwise, unless your proven to be stealing and selling data, let there be strong legal protections for those who responsibly report vulnerabilities.
And this is practical too. With vulnerability bounties you can solve the problem just by throwing money at it. But bounties can't be an opt-in thing, the companies who need them most are not opting-in.
My conspiracy theory is that my idea will never be implemented because it would expose the "job creator" class to an objective measure of their competence, and they would not fare well. Headlines like "97% of US organizations are incapable of building secure systems" would not be fun.
Attackers would have to social engineer the MVNO directly, which is certainly easier if they have data they’ve stolen from t-mobile first, but this isn’t a “they’ll get in no matter what because they’ve pwned T-Mobile so bad” scenario.
This article says that Google Fi customers were SIM swapped due to a T-Mobile breach. Even though "[t]here was no access to Google's systems or any systems overseen by Google."
> As the Google Fi data breach includes phone numbers, which can easily be linked to a customer's name, and the serial number of SIM cards, it would have made it even more convincing when contacting a mobile customer support representative.
They used the data in the breach to social engineer the Google fi reps. Attackers still needed to get through Google’s customer support system to perform the SIM swaps.
Although, "bills" reminds me - a lot of companies overload the use of 2FA SMS for both identification and 2FA purposes, not to mention most customer service centers expect the call to originate from the same number that receives 2FA SMS messages for authenticating to the account being serviced.
If we need to legislate something, perhaps we should try to discourage this sort of thing in the first place. One company should not be allowed to paint a target on an uninvolved company for financial gain.
Is the customer not paying for the cell phone plan? Nothing is “no cost” in this situation. The cost is just shifted to the consumer from the company in the form of requiring a phone number.
> One company should not be allowed to paint a target on an uninvolved company for financial gain.
Or, if T-Mobile and others did a good job in security for their networks and in turn their customers communications maybe they wouldn’t have this issue.
IMO this comparison would be like claiming a gas station is responsible for your cars electronics not functioning properly.
About 2 months ago I noticed $15 charges very cleverly disguised as Amazon prime. The only giveaway was that it said the number was entered manually.
Everyone with T-Mobile autopay should check immediate for an Amazon prime charge that was manually entered.
I have an iphone with esim and 2FA on most things, but there are still use cases that send codes via text.
To minimize phone number exposure, you want to send the phone number to as few third parties as you can. You don't want it to show up in any databases, including in breached databases from hacks of companies where you stored your phone number for 2FA purposes. Unfortunately this means the only true solution is a unique phone number per account with SMS 2FA, but that's obviously not practical. So what can you do?
A VOIP number like one from Google Voice is the next best solution for receiving 2FA SMS codes to a dedicated number that you keep separately from your personal phone number. This way you receive texts purely through software and don't expose yourself to SIM swapping at the Mobile ISP level. Unfortunately, some providers won't accept Google Voice or VOIP numbers, so for them you're back to square one... maybe as a backup option (only for those sites), you could use a cheap phone with a pay-as-you-go plan; it's not great, because you're still vulnerable to SIM swapping, but at least you have a dedicated number for SMS 2FA.
Looking at the problem more widely, it would be nice if my phone or mobile ISP could solve this problem for me, with something akin to disposable phone numbers (think Apple Private Relay, or temporary credit card numbers from the bank) or a dedicated 2FA code relaying service (think Authy or Google Authenticator - in fact, maybe they could offer SMS numbers as a feature, although that seems at least as dangerous as the status quo).
https://www.cnet.com/tech/mobile/t-mobile-is-dropping-its-au...
If your snappy upstart cellular network can't afford to give out Yubikeys to employees, I don't want you interconnecting with the rest of the phone system.
I planned and did the roll out of Yubikeys at the last place I worked, before there was a dollar in sales, and the lifecycle could be supported with 2 people (minutes at most out of each day for support) and an integration to our HR platform that automated procurement and mailing of keys.
In practice, what are the barriers to adoption which folks are seeing, and what can we do about it?
I think the biggest barrier to adoption is lack of end user demand for the service. That is followed by people not understanding/believing the incredible increase in user experience and security. It's almost like people think it is too good to be true.
Don't use a mere mobile number for the backup access to anything inportant!
That said, perhaps everybody using SMS 2FA is equally culpable (e.g. most banks). Nobody who has worked at a mobile carrier would ever think that they're ready to be high-value targets. So it's puzzling that the banks are so eager to put them in that position.
1. Businesses using insecure channels to do authentication and validation.
2. Mobile carriers
I'm imagining an authorized pen-tester program which lets authenticated users achieve an atomic sim-swap (i.e. the creds were intercepted but the swap-back occurred immediately after, so as not to deny additional service to the victim).
" Initial carriers that have signed up to Open Gateway are América Móvil, AT&T, Axiata, Bharti Airtel, China Mobile, Deutsche Telekom, e& Group, KDDI, KT, Liberty Global, MTN, Orange, Singtel, Swisscom, STC, Telefónica, Telenor, Telstra, TIM, Verizon and Vodafone. "
Link: https://techcrunch.com/2023/02/26/mobile-carriers-team-up-wi...
[Edit] The more I think about this, perhaps another path to resolution would be to remove limited liability protections from companies that repeatedly put their customers at risk, especially given that phones are used as financial transaction authenticators. Perhaps some bank regulations need to find their way onto cellular providers.
I think you are correct. I don't like the idea of making a giant-bell yet once again but I also don't see a way to correct T-Mobiles obvious cavalier and brazen incompetence. Fines? Companies just factor that into the cost of doing business. Threat of losing their FCC license? I think collusion between business and government would drag that fight out for decades and probably even exacerbate the problem. March their leaders through town with a shame-nun? I don't know what would get real results quickly. Tack on some bigger fiduciary liabilities since phones are used to authenticate bank transactions?
Perhaps if some powerful political leaders had nasty secrets revealed or lost money as a result of these hacks there might be action but that is a big if. That might never happen and that also assumes there is proper attribution.
Yes and yes. We're down to three big mobile telecoms now, ATT, Verizon, T-mobile/Sprint. At least MVNO's are allowed though, plenty of those.
[0] https://www.federalreserve.gov/newsevents/testimony/alvarez2...
Uhhh ... hard pass.
https://plaintextoffenders.com/post/4567498592/t-mobilenet
And more recently in 2018:
https://plaintextoffenders.com/post/174100751368/meint-mobil...
A few more in the master list here:
https://github.com/plaintextoffenders/plaintextoffenders/blo...
To defend against port-out you should enable port protection. The name of such a feature varies by carrier, and T-Mobile seems to refer to it as "Takeover Protection."
https://www.gsma.com/futurenetworks/gsma-open-gateway-api-de...
It seems it should solve the SIM Swapping problem with an extra verification step, if the carriers have things right I guess.
> Addressing these issues requires a long-term approach and not simply a new set of regulations or industry standards. Easterly said it will require the leaders of technology companies to focus explicitly on building safer products, provide transparency into their development and manufacturing processes, and an understanding that the burden of safety should not fall solely (or even mainly) on customers.
I'm right now struggling to get a bunch of US IoT companies to agree on a very basic set of security standards that would allow more interoperability. All we're asking are basic best practice to anyone working in security (e.g. ETSI 303 645). And the reason why I'm struggling is because in the EU these baselines are becoming the law as of 1st Aug. 2024 with the Radio Equipment Directive (RED). And in addition these same kind of guardrails will also become law with the Cybersec Resilience Act in 2025 expanded to the cloud and mobile apps. So this thing is coming and the US which has a lot better standards (thanks to NIST but lacks legalization due to power of lobby groups) looks like a total laggard here to a point where it becomes embarrassing.
Nobody in their right minds would argue there are unreasonable provisions in these proposals for RED (or the CRA). Yet all the US based vendors who do not sell into EU markets shout "bloody murder".
And it's hilarious how they're all grandstanding about "how dare the communist EU is telling business how to innovate".
Legislation works. Begging vendors to come up with better controls by themselves will not.
Anyone who has spent even a single day working in security in a company where security isn't part of their core value proposition (or isn't _the_ product) will know the only way to enforce even the most basic security and safety controls[2] is by legislation.
You want a unified charging standard for EV? Make it the law!
You want a single type of charger for all phones? Make it the law.
You want your coding standards to meet guidelines for functional safety? Make them law.
You want to eliminate OWASP Top-10 from production code? Make it the law.
[1] https://duo.com/decipher/strong-security-has-to-be-a-standar...
[2] entirely related: The Humble History of the Crash Test Dummy https://www.motorbiscuit.com/the-humble-history-of-the-crash...