4 ms·
As usual they don't say how this was accomplished. They call it "sophisticated" but it probably was just stupid or lazy, which is very common in most corporate
by coldcode 5y ago
As usual they don't say how this was accomplished. They call it "sophisticated" but it probably was just stupid or lazy, which is very common in most corporate hacks. Big companies don't really care much about security since it costs money and rarely causes much trouble to your stock price and exec compensation.
The people who suffer are those whose data is compromised and have no idea it happened.
- toomuchtodo 5y agohttps://twitter.com/damienmiller/status/1427195852011937797 https://twitter.com/damienmiller/status/1427195852011937797
- gjsman-1000 5y agoOpenSSH from 2014. That'll do it.
- deleted 5y ago[deleted]
- gurchik 5y ago> That allowed the person to eventually pivot to the LAN. Once on the LAN, the same person claims the data was "sitting in plaintext on an insecure backup server": https://twitter.com/und0xxed/status/1427639599636041742 https://twitter.com/und0xxed/status/1427639599636041742
- mjevans 5y agoCopy of the tweet for preservation: Damien Miller @damienmiller Looks like T-Mobile hasn't updated the OpenSSH installation (and thus probably neither OS) since 2014. SHA256 has been the default hostkey fingerprint since the openssh 6.8 release in 2015 Retweeted: https://twitter.com/Jeremy_Kirk/status/1427144723731402756 https://twitter.com/Jeremy_Kirk/status/1427144723731402756 Jeremy Kirk @Jeremy_Kirk The person who claims to have compromised T-Mobile says the company misconfigured a gateway GPRS support node that was apparently used for testing. It was exposed to the internet. That allowed the person to eventually pivot to the LAN. Proof screenshot supplied.
- jasonladuke0311 5y agoThey probably put more money into that banner than into keeping these systems patched. That there banner was probably a dozen plus hours of legal work. :(
- A4ET8a8uTh0 5y agoI can agree. At one of my previous employers, IT management was adamant that no password vaults of any kinds could be used. It was a bigger company with tons of various systems to get into all with different sets of requirements. So what was the result? Average user ended up storing passwords info in excel and text files. Yay. I think only recently there was some movement to approve a vendor there.
- harikb 5y agoSomeone did put the blame on COVID! Not sure if it is Tmobile or Reuters From a Reuters article on same news https://www.reuters.com/technology/hackers-steal-some-personal-data-about-78-mln-t-mobile-customers-2021-08-18/ https://www.reuters.com/technology/hackers-steal-some-person... > T-Mobile’s data breach is the latest high-profile cyberattacks as digital thieves take advantage of security weakened by work-from-home policies due the COVID-19 pandemic
- imnotlost 5y agoDid someone take the database computer home?
- geoduck14 5y agoI HATE it when that happens!
- jrootabega 5y agoOh boy, somebody's gonna lobby for all banks and telcos to be legally barred from remote work.
- u801e 5y agoOthers should point out that these breaches were happening even with people working from the office.
- jrootabega 5y agoYes, Senator, but those breaches weren't as breachy as this one.
- midwestemo 5y agoThe OpenSSH they were using was from 2014/2015 so they probably didn't update the OS or anything at all for a while
- chefandy 5y agoSophistication is contextual. Among computer criminals, exploiting unpatched or poorly credentialed systems is unimpressive. In the context of the animal kingdom at large, it's astonishing.