Well, the forums are abuzz with voyeurs and conspiracy theorists trying to figure out the latest T-Mobile Sidekick hack.
It's a hoax or a twisted PR move. I looked at the pictures. Ya, all of them. I don't think these are all Sidekick pictures. In fact, I not sure any are. Here's why.
1) EVERY picture is of Paris. Where are the pictures of friends at an event, or at a bar? Also, her makeup and hair are perfect in every picture. Where are the no makeup, hair down, pictures? She would have to be as self centered as the "media" says she is for me to believe these.
2) The topless pictures seem to have a fog around the edges. I know there is a special lens that does this, but I've never seen it on a Sidekick.
It's real.
1) I've read too many forum entries of people gutsy, err inconsiderate, enough to call some of the phone numbers. Filled mail boxes, real people hanging up on the caller, and disconnected numbers all point at these being real numbers. Even if these aren't the numbers to the stars, it is unlikely a planned PR stunt would include the phone numbers and e-mails of real people.
2) If T-Mobile was complicit in this "stunt", it would be like staging a train wreck in hopes of getting your railroad some additional press. Unfortunately, celebrities who wish to stay in the spotlight DO stage train wrecks in search of publicity. Maybe this point should go under "undecided".
Undecided. That's where I'm at today. Some things look mighty fishy, but this is just too ugly to be a stunt or a hoax.
Now for the Wireless take on this.
This is not the first news of T-Mobile's Sidekick users getting hacked. I blogged this same issue a month ago. I also posted some precautions to take.
My recommendation: If you are a T-Mobile customer, be assured that all indications are that your personal information is safe. That being said, I would recommend that all T-Mobile subscribers who use My T-Mobile or the SideKick services change their account passwords, more for piece of mind than necessity. Besides, it is always a good practice to change passwords periodically anyway.
I would also add that as long as you are not a publicity starved model, or absent minded Secret Service agent, you shouldn't need to worry too much. But again, it's better to side on the safe side, and change your passwords more than once in a lifetime, don't use your dog's name for your password, and if security is at all a concern, get a BlackBerry. Some of the media outlets have referred to Paris' phone as a BlackBerry. This is wrong. It was a Sidekick.
I though T-Mobile dodged a bullet with the deafening silence around the last hacking story. I think people will pay a little more attention to this shot.
Showing posts with label Sidekick. Show all posts
Showing posts with label Sidekick. Show all posts
Monday, February 21, 2005
Wednesday, January 12, 2005
T-Mobile Hacked
SecurityFocus.com just broke a story of a pretty significant breach of T-Mobiles computer systems. Life in the wireless world just got a lot tougher. For users, their comfort and confidence just took a big hit. For those of us who sell wireless, security just moved from the benefit column to the challenges column. The main reason for this level of impact is not because of this incident alone, but due to the implications that it could happen again. It's hard to worry about something that has never happened. It's easier to worry when you can point at even one situation where it did happen.
Even though T-Mobile has not responded to the story yet, I do want to share some of my observations to help put this in a proper perspective. The sky is NOT falling in wireless security. Some plaster has been shaken loose though.
The Bad News: The hacker got names, Social Security Numbers, and birth dates for many customers. The hacker also got pretty deep into the SideKick server. This server relays messages for SideKick users. It also can store on-line copies of the users contact list and calendar if the customer chooses to do so. Here, the hacker got SideKick account passwords, SIM numbers and IMEI's. These are basically serial numbers for the SideKick and the "Subscriber Identity Module" that is in the SideKick. The biggest news is that one of the SideKick users that the hacker monitored was the Secret Service agent tracking the hacker. The hacker also copied some of this agents SideKick e-mails off of the SideKick server. Some press reports make it sound like the hacker pulled them directly off of the SideKick. This is HIGHLY unlikely, and unnecessary since all SideKick e-mails pass through the server that was hacked.
Good News: According to T-Mobile, everyone who's accounts were compromised has already been notified of the breach. If you haven't been notified, you are probably safe. Although the breach of the SideKick server is serious, there is no indication of a breach of the BlackBerry Web Client (BWC). The BWC is a similar server for BlackBerry users and is hosted by RIM. Knowing quite a bit about the security involved with the BWC, it is safe to say that this breach had little, if any, impact on the BlackBerry services. Here is a great reason to choose BlackBerry and a BlackBerry Enterprise Server (BES) over any Web Hosted solution. The BES is a server that the customer hosts themselves, behind their own firewall, and that they have total control over.
My recommendation: If you are a T-Mobile customer, be assured that all indications are that your personal information is safe. That being said, I would recommend that all T-Mobile subscribers who use My T-Mobile or the SideKick services change their account passwords, more for piece of mind than necessity. Besides, it is always a good practice to change passwords periodically anyway.
This is not a pretty situation, but understand that this kind of breech is not unique to your wireless carrier. I know, that is not very reassuring, but the truth is that these same kinds of breeches have occurred with banks, airlines, medical insurance companies, and many other businesses. For those of you directly affected by these events, I understand the tragic impact this can have. For everyone else, understand that this is one of the risks of the information age. For anyone interested in law enforcement, may I recommend cyber-security as a career. This truly is the "wild west" of modern crime and lawlessness.
I'll probably comment more when I see what T-Mobile and others have to say over the next couple days.
Even though T-Mobile has not responded to the story yet, I do want to share some of my observations to help put this in a proper perspective. The sky is NOT falling in wireless security. Some plaster has been shaken loose though.
The Bad News: The hacker got names, Social Security Numbers, and birth dates for many customers. The hacker also got pretty deep into the SideKick server. This server relays messages for SideKick users. It also can store on-line copies of the users contact list and calendar if the customer chooses to do so. Here, the hacker got SideKick account passwords, SIM numbers and IMEI's. These are basically serial numbers for the SideKick and the "Subscriber Identity Module" that is in the SideKick. The biggest news is that one of the SideKick users that the hacker monitored was the Secret Service agent tracking the hacker. The hacker also copied some of this agents SideKick e-mails off of the SideKick server. Some press reports make it sound like the hacker pulled them directly off of the SideKick. This is HIGHLY unlikely, and unnecessary since all SideKick e-mails pass through the server that was hacked.
Good News: According to T-Mobile, everyone who's accounts were compromised has already been notified of the breach. If you haven't been notified, you are probably safe. Although the breach of the SideKick server is serious, there is no indication of a breach of the BlackBerry Web Client (BWC). The BWC is a similar server for BlackBerry users and is hosted by RIM. Knowing quite a bit about the security involved with the BWC, it is safe to say that this breach had little, if any, impact on the BlackBerry services. Here is a great reason to choose BlackBerry and a BlackBerry Enterprise Server (BES) over any Web Hosted solution. The BES is a server that the customer hosts themselves, behind their own firewall, and that they have total control over.
My recommendation: If you are a T-Mobile customer, be assured that all indications are that your personal information is safe. That being said, I would recommend that all T-Mobile subscribers who use My T-Mobile or the SideKick services change their account passwords, more for piece of mind than necessity. Besides, it is always a good practice to change passwords periodically anyway.
This is not a pretty situation, but understand that this kind of breech is not unique to your wireless carrier. I know, that is not very reassuring, but the truth is that these same kinds of breeches have occurred with banks, airlines, medical insurance companies, and many other businesses. For those of you directly affected by these events, I understand the tragic impact this can have. For everyone else, understand that this is one of the risks of the information age. For anyone interested in law enforcement, may I recommend cyber-security as a career. This truly is the "wild west" of modern crime and lawlessness.
I'll probably comment more when I see what T-Mobile and others have to say over the next couple days.
Subscribe to:
Posts (Atom)