T-Mobile Hacker Explains How He Breached Carrier's Security (axios.com) 26
According to the Wall Street Journal, the person behind T-Mobile's recent security breach that affected more than 50 million customers is a 21-year-old named John Binns. " Binns said he broke through the T-mobile defenses after discovering an unprotected router exposed on the internet, after scanning the carrier's internet addresses for weak spots using a publicly available tool," reports Axios. From the report: "I was panicking because I had access to something big," he wrote in Telegram messages to the Journal. "Their security is awful." "Generating noise was one goal," Binns said. He declined to say whether he sold any of the information he stole, or whether he was paid for the hack.
Some of the information exposed in the breach included names, dates of birth, social security numbers and personal ID information. The breach is being investigated Seattle's FBI office, according to the Journal.
Some of the information exposed in the breach included names, dates of birth, social security numbers and personal ID information. The breach is being investigated Seattle's FBI office, according to the Journal.
Everyone knows. *wink*nudge* (Score:2)
"Publicly available tool" I think we all know that one.
Re: Everyone knows. *wink*nudge* (Score:2)
Asshole (Score:5, Insightful)
From what little parts of TFA I read...
He was scared because of what he found. Did he ever consider telling T-MOBILE rather than breaching the systems and grabbing the data?
Re: (Score:1, Troll)
You're confused, the real criminals here are T-Mobile. They should get the worse punishment.
Re: (Score:2)
Are you sure? I could swear the router was dressed provocatively.
Re: (Score:2)
Not only that, it has a reputation for exchanging packets promiscuously.
Re: (Score:1)
Re: Asshole (Score:2)
The problem is not that tmobile left a door open guarding their own stuff. The problem is that tmobile put their clientâ(TM)s stuff on a busy street and âoeprotectedâ it with a sign.
Re: (Score:2)
If you put your money in a pile on the front sidewalk, don't whine like a bitch the next morning when its gone.
Telco have been infamous for decades for leaving default passwords on gear, going back to the first Unix based switches.
Quit being a shill for the incompetent and stupid, you're wrong and ignorant. Your point of view would end civilization if adopted, that's how stupid you views are.
Re:Asshole (Score:5, Insightful)
All too often people do the right thing and alert the company. Of course then blame is placed on you for embarrassing said company. If you find something like this then keep your mouth shut. No good deed goes unpunished.
Does it even matter anymore? (Score:2)
Re: (Score:2)
Correction: All of our information that we thought was private but wasn't, is now known to certainly not be private.
Re: (Score:3, Interesting)
All of our formerly private information is completely public by now. Does it really matter that another company exposed our SSN, drivers license, postal address, etc anymore? Freeze your credit lines and move on.
Underpaid Experian Call Center Employee (UECCE): Hello, thank you for calling Experian. How can I help you today?
Not BeerFartMoron (NBFM): I, uh, "lost" my credit freeze PIN number number.
UECCE: Oh, I can help you reset that by having you answer a few questions that only you will know the answer. [bankrate.com]
NBFM: [Hehehe] Sure, go ahead.
UECCE: What is your SSN?
NBFM: [Checks Experian data leak] BER-FRT-MORN
UECCE: And your current employer?
NBFM: [Checks Dell data leak] DumbStuph, LLC
UECCE: And your date of birth?
NBFM:
Re: (Score:2)
It's worse than that... Often the "security" questions are things like "mothers maiden name" or " what school did you attend" etc...
This data doesn't just leak online through security breaches, people VOLUNTARILY post this information online these days!
Mothers maiden name? look up your family connections on facebook, your grandparents will still have your mother's maiden name, your uncles and cousins likely will too. Otherwise look up family tree on one of those ancestry sites.
School? People put the school
Re: (Score:2)
These companies don't check that the information you give is correct. They only care that you remember what you gave them.
Mother's maiden name? Miss
3rd grade school name? Elementary
Name of your first pet? Helium
Make of your first car? Oxygen
City where you met your wife: Carbon
It does require you to record these answers and not duplicate them at every site, but a data breach doesn't give the bad people any additional personal information.
--
All my pets are named after the noble gases.
Re: (Score:2)
My former boss gave me an even easier technique:
All of the answers for a given company are the same. So when I'd call up the company's "Enterprise Service Desk", all of the security answers were "blue". I didn't even have to wait for them to ask the question.
If they had a "what's your favorite color" question, I would've chosen a non-color answer, so that the answers make no sense given what the questions are.
Then you just need to match up the company to your (single) answers, rather than have to keep tra
Re: Does it even matter anymore? (Score:3)
Americans are strange. In my country there is zero chance that any password or pin or anything security related could be changed over the phone. You can disable credit cards and stuff, but you can never get any new credentials over the phone. All this yankee âoeidentityâ that relies on a photoshopped utility bill is quit hilarious.
Re: Does it even matter anymore? (Score:2)
John Binns (Score:5, Insightful)
And is now doing interviews and laughing all the way to the bank?
Yea I know T-Mobile is at fault for weak security. But this guy is scum of the earth.
Re: (Score:3)
Re: (Score:2)
And maybe he gets stabbed on the way to the bus. Who knows. He's pissed off some wealthy people.
don't drop the soap and enjoy paying for there up (Score:1)
don't drop the soap and enjoy paying for there upgrade at the $0.15/hr prison work rate.
Credit Repair (Score:1)