Vodafone Hacker Accesses 2 Million Customers’ Banking Data
businessweek.com
businessweek.com
Am I correct in understanding that the data stolen is Vodafone's customer payment details (ex: for auto payments)? At first read I thought that Vodafone had gotten into banking but I don't think that makes sense.
> The hacker had no access to credit-card information, passwords, PIN numbers or mobile-phone numbers, Vodafone said.
Credit card numbers and passwords I can understand as not being accessible (both can be either escrowed or hashed) but I don't see how it's possible to not have access to mobile phone numbers. If Vodafone is anything like US carriers then your phone number is basically your account number (sometimes a couple extra digits, ususally nothing though). Does anyone really think they have a separate account # per customer with the just the above data referenced to it?
Although to the customer it may appear that your phone number is your account number, that normally isn't the case. This is for a number of reasons:
* Phone numbers can change either through porting or by choice (i.e, due to nuisance/harassment, etc)
* Single 'accounts' can have multiple phone numbers (i.e, a family plan)
* Some plans may have phone numbers that are opaque to the user (i.e, 3G dongles, etc)
In the carrier systems I've seen / worked on there has normally been a unique account identifier that isn't the MSISDN.
Status quo is maintained.
With this in mind, why should anyone feel sorry for someone being punished for a crime they committed?
EDIT: After reading the comments below, I guess I need to clarify what I said. I put it badly to say the least; I should have said "property damage" instead of financial damage.
I do think that demanding some actual, demonstrable financial cost be presented before a hacker can be tried is an extremely dangerous precedent, though. A real world analogy would be if I pick the lock and enter your house without your consent, stand in your room watching you sleep, then leave, all without causing any damage. I haven't caused you any financial damage, but I should certainly be arrested and charged for it.
But actually, fuck that dude. Vodaphone isn't the victim really. I am. Now phishing emails sent to me will be better, and can include data that I previously used to verify legitimate emails. Now I have to sort out all my bank accounts and have new numbers issued. Now I have to think about how I deal with the fact that the answers to common security questions are in the "hackosphere" for sale.
So no. I don't care about the financial damage. The guy has effectively sprawled graffiti on 2 million peoples lives, which they have to clean up. I'll reserve my sympathy for people who are at least are well intentioned...
Instead, it is likely that you're advocating for firing a modestly compensated engineer whose crime is shared by substantially every production system everywhere.
I wonder now how things might be now. Would folks think a bit more about deploying busted web sites?