T-Mobile Breached, Again
arstechnica.com
arstechnica.com
wow, pretty much everything. great. How have they not learned from the last SEVEN times?! Can they be sued for this? Can they be fined by the government for this?
I just logged in and when I tried going to my profile section I just got a screen that said "Access restricted". Maybe because I'm logging in from my work laptop which I've never done before. I guess this is how they are trying to deal with the issue, preventing access of sensitive info from "suspicious" logins.
The system is broken. There is no accountability whatsoever. You have no power to change any of this. It's all fucked.
Then, once the SSN can't be plausibly relied upon to authenticate people, these industries will have to do the hard work themselves.
The 2017 Equifax breach was 40+% of americans. As far as I can tell, it barely changed anything about using SSNs as username and password for identity and credit. It maybe helped end user fees for credit freezes. Based on the response to that breach, I don't think a full dump would change anything either. I don't know what it was like before this breach, but identity fraud doesn't seem to get any investigation these days --- a year or so, someone rented an Oakland luxury apartment and tried to open two credit cards in my spouse's name and social security number, and Oakland PD didn't follow up at all.
That's what I'm hoping for. A full database dump of everybody's SSN that's made embarrassingly public, so people can see just how useless SSNs are. I could enter "Marvin Garrison, DOB 1974-04-20" and get Marvin's SSN.
A torrent file, made available for even a short period of time, would be preserved forever and put the final nail in the coffin.
I know this sounds like some nerd version of Fight Club, but I stand by it :)
Sure, there will be duplicates. John Miller, born on 10/10/1963 will happen a dozen times maybe. Will still be effective in destroying the SSN as a magic key.
Are there companies with a worse track record than this? Seems like they get breached way more than average.
Unless the press or some independent researcher like Krebs digs something up, its often times rare a company will make this stuff public.
The intrusion lasted that long and only data of 836 subscribers was affected?
That's a weirdly low figure for having over a MONTH of access to their systems. What did they hack, a barely used fax-machine?
I can't imagine a provider being hacked in the EU 9 times being able to get away with not changing its practices/being fined into oblivion.
You need to show evidence you’ve had your identity stolen before you can safely prevent it from happening. The whole industry is exactly backwards.
There is no way in hell I’m giving T-mobile my checking account info.
This number seems oddly low. My first instinct is not to trust that this was reported honestly. But if it is accurate, why was it so low? Perhaps there's something else very interesting about this breach they're not disclosing (not that they would provide more than the bare minimum amount of information required anyways).
Seriously, when I switched from T-Mobile postpaid to T-Mobile prepaid it was like changing carriers. New SIM, different website, mobile app does not work with prepaid accounts [1], different payment methods accepted, and more.
If it weren't for the branding and the prepaid website being a subdomain of t-mobil.com someone looking at both would not guess that they are the same company.
[1] It says "Sorry we're not ready for you. We're working on improving your app experience". It's been that way for many years, and whenever anyone asks about it on the T-Mobile forums someone from T-Mobile says they are working on it.
Make some bare minimum changes due to budget constraints.
Get hacked again.
Make a statement.
Hire security consultant.
....
It's just a hassle to move so I stay because of inertia (read: laziness).
I can revoke a cert that has been compromised. I don't understand why we don't have a similar procedure set up for my PII.
Any requirements imposed at a local store are specific to your State. If you really want to get one without providing any PII, get the line in a different State.
Not providing information is the first step of limiting the blast radius of data leaks.
https://github.com/n0sec1/n0sec-blog/blob/main/data/blog/how...
How many times is it going to take for them to actually take this seriously?