3 ms·
You know, I’m starting to become slightly more serious about switching carriers solely based on how terrible it would be to experience SMS/Call diverting of my
by testfrequency 4y ago
You know, I’m starting to become slightly more serious about switching carriers solely based on how terrible it would be to experience SMS/Call diverting of my number.
While I use a yubikey, OTP (where possible), and unique passwords…there’s still places where I have no choice and my number is my auth (or stupidly a reset option).
I genuinely am happy with TMO service in the US, and frankly abroad it’s excellent…but I’d be lying if every single article I see about their security breaches reminds me I may be on borrowed time myself.
- welder 4y agoUnfortunately, most carriers (except ATT & Verizon) are just T-Mobile resellers... so you might think you're not using T-Mobile but you're still affected. Even if you use ATT or Verizon, the article mentions they're also hacked and SMS intercepted often.
- forbiddenlake 4y agoCan you source "most" and define "carrier" specifically for your comment? Verizon and AT&T are the other of the big 3 carriers in the US, and they're not reselling T-Mobile. And all 3 have MNVOs (mobile virtual network operator) that resell and/or combine the networks of the big 3.
- testfrequency 4y agoHonestly, I’d assume being on a MVNO carrier would actually protect you from this, as you’re simply roaming on the T-Mobile network through the carrier agreement. Even ATT and Verizon have roaming agreements. The issue is for T-Mobile direct customers, which obviously their internal systems have access to. I see no reason why T-Mobile would have access to users accounts at another company…
- plexicle 4y agohttps://www.theverge.com/2023/2/1/23580947/google-fi-mobile-tmobile-security-breach-data https://www.theverge.com/2023/2/1/23580947/google-fi-mobile-... "Google says that hackers may have accessed limited customer information via the compromised system, which includes phone numbers, SIM card serial numbers, account status, and mobile service plan data. The system did not contain personal customer information such as names, email addresses, payment card data, government IDs, passwords, or pin numbers." It's something, but not perfect.
- 310260 4y agoIt depends on the MVNO. Some have their own backends. Others only do the marketing and leave the backend to the carrier. MVNOs do not roam on the carrier, however. The MVNO has a close direct relationship for wholesale access to the network. Roaming is a wholly separate method of access.
- Arnavion 4y agoEg in the 2021 T-Mobile breach, Ting MVNO claimed their users' data was not affected: https://help.ting.com/hc/en-us/community/posts/4405384603291-T-Mobile-Hacked-Data https://help.ting.com/hc/en-us/community/posts/4405384603291... Of course you'll still be affected by SIM-swapping etc that just change how your number itself is routed.
- flanbiscuit 4y agoSo that leaves Verizon, AT&T, and Dish networks[1] And all of them have supposedly been compromised, but T-Mobile is the most compromised. > While it is true that each of these cybercriminal actors periodically offer SIM-swapping services for other mobile phone providers — including AT&T, Verizon and smaller carriers — those solicitations appear far less frequently in these group chats than T-Mobile swap offers. And when those offers do materialize, they are considerably more expensive. So the choice is, which one is the least compromised, unfortunately 1. https://en.wikipedia.org/wiki/List_of_United_States_wireless_communications_service_providers#Largest_U.S._wireless_providers https://en.wikipedia.org/wiki/List_of_United_States_wireless... technically there are a bunch other small carriers that run their own equipment (not resellers), more than I thought there were: https://en.wikipedia.org/wiki/List_of_United_States_wireless_communications_service_providers#Facilities-based_service_providers https://en.wikipedia.org/wiki/List_of_United_States_wireless...
- testfrequency 4y agoSpeaking of Dish, the entire company and their services just breached this past week.. https://www.theverge.com/2023/2/28/23617347/dish-cybersecurity-incident-internal-outage-customer-support-employees https://www.theverge.com/2023/2/28/23617347/dish-cybersecuri...
- Spooky23 4y agoTMobile seems to be particularly bad right now, but Verizon and AT&T aren’t necessarily good. The weak link is usually retail or channel. TMobile is in a high growth phase, so I’d hazard to guess they are more disorganized. Switching to Verizon may reduce exposure, but they have their own similar issues - an aggressively dumb carrier employee is capable of almost anything.
- testfrequency 4y agoAs sad as it is to write this, Apple corporate lines are Verizon - though they also have ATT available if you need it or have a preference. I only say this as I don’t know of any major corporation who picks TMO as their company lines. All this to say, I trust ATT and Verizon slightly more than T-Mobile
- Spooky23 4y agoThe corporate accounts are a little different, but people like retail employees can do damage. You can control SIMs out of band in some cases.
- thrashh 4y agoI think the issue is that phone companies weren’t prepared for their services to be used for such high security tasks. For many decades, your phone was just mostly for keeping up with friends and family. 2FA wasn’t even that popular until maybe in the last 10 years. Just like how the locks we buy for our exterior doors are really weak but that’s currently fine for the status quo. You’re not going to preemptively spend money to upgrade your locks.
- delfinom 4y agoYep, using SMS for 2FA is the same as colleges using your social security number as ID on everything back in the day. It absolutely was never intended for the use case.
- nebula8804 4y agoAlso consider that T-Mobile as it exists is the result of years/decades of mergers and acquisitions so they have decades of legacy and non-conforming systems. This situation is bound to cause security issues as well. I had a family member work for an MVNO that interfaced with them and this is what she saw.
- pitaj 4y agoOn that topic, does anyone know about a good alternative that can be used just for a secure SMS number? Google Voice has been mentioned several times but it's unclear to me how that helps.
- dbmnt 4y agoIt helps. I try to use an authenticator app whenever possible, but use a Google Voice number if a service requires SMS-based auth. The trick is to not forward the texts to another cell number. You can either view them using the Voice web interface, or forward them to your Gmail on the same account. Then lock that Google account down as much as possible. I use Advanced Protection (https://landing.google.com/advancedprotection/ https://landing.google.com/advancedprotection/). This is WAY more secure than using T-Mobile or another cell provider's SMS.
- e40 4y agoIt's the sole reason I'm still with Google Fi, the fear of sim swaps and my (hopefully not mistaken) belief that Google Fi is less hackable than the big 3. I've certainly read that here, many times.
- SkyMarshal 4y agoI'm on TMO in the US and haven't ditched it yet for the same reasons. I just take all possible precautions. Namely, never use your TMO phone number for any kind of 2FA on other services. Use TTOP, Yubi, and if those aren't available on a particular service then Google Voice for SMS 2FA. If GV isn't allowed, then obfuscate your username, password, and disable account recovery on that service, among other precautions (or just don't use that service at all, find a replacement).