T-Mobile responds to Paris Hilton Sidekick hacking
It's not much more than just the usual type of generic press statement you'd expect after something like this, but T-Mobile has just issued an official response to the whole Paris Hilton hacked Sidekick "incident":
T-Mobile is investigating the reported disclosure of Paris Hilton's information.
T-Mobile's computer forensics and security team is actively investigating to determine how Ms. Hilton's information was obtained. This includes the possibility that someone had access to one of Ms. Hilton's devices and/or knew her account password.
Given the sensitivity of the situation, and to protect our customers' information, we are not able to provide specific details of the investigation at this point.
Obviously no one seems to know for certain how this all happened, but they've got to be praying right now that it turns out that she accidentally gave someone her password.

















Yeah, here's the likely culprit
User name: paris
Password: hilton
or
username: paris
pw: iloveme
YAY! Stupid spoil whores make big news! 3 times! Humans are such interesting animals. :)
We actually took a poll on possible passwords, we think it was one of the following:
iswallow
247smirk
ifvck
password
raisins
0000
and lastly
12345
We actually just changed over one our customers numbers who was on her phonebook, he recieved 2000 missed calls, Tmobile was glad to change over the number..
I think T-Mo is just covering its ass. They know how it all happened and don't want to share it because, one they don't want more hackers coming in since they can't close the gap yet (they are too stupid) two, they don't want to lose anymore customers that will probably take their asses to court trying to get out of the contract not trusting them any longer. To me, T-Mo is putting the blame on Paris. If she smart she should tell them to go FVCK themselves, have her lawyers take them to court and join another cell phone company. My wife used to have a Sidekick Color and after dealing with the nastiest customer service department I am glad she no longer has their service. Its a pretty popular device for deaf people and I wish Nokia would get off its fat ass and design something to crush them. No, the 9500 and 9300 are way too expensive. Blackberry are not good at AIM which would be what deaf use in place of the voice service.
sex tapes, personal pictures, it seems that Miss Hilton is bad at keeping her life private but at least she is enjoying the fame (infamy) it brings. Some people might think she actually likes all the attention, afterall, she would be nobody to most people in the world if these 'intrusions' hadn't happened.
Everybody keeps blaming TMobile When.. IF there WAS hacking going on.. it's Dangers fault.. they handle the data part of the sidekick. When u call Tmobile when you have problems with your sidekick data.. they send you to DANGER sidekick data department
I hope that someone hacked the crap out of it.
Otherwise it would be really boring for the rest of us "normal" people, wouldn't it? I mean we already know she's as thick as two planks, and nothing more is needed to confirm that......
If the dumb b*tch gave up her password, than this is the sweetest pwnage of the season. Maybe we can get a Fox series where she appolgizes personally to everyone whose number she compromized by performing some of her usual video antics.
Producers: I've already written and pitched this, it's MY IDEA. Steal it and you will be facing your own Fear Factor scene, get me?
-Deadpan. They keep stealing my ideas.
O-B-V-I-O-U-S P-U-B-L-I-C-I-T-Y S-T-U-N-T. Gee, she gets out of her contract with T-Mobile, and another two weeks of exposure . . . without paying a dime. That's just too easy a deal NOT to suspect that the whole thing's a fraud.
At this rate, we'll be reading about lawsuits stemming from this episode for years.
Sadly, the circus-like atmosphere surrounding this story clouds the real issue: data security on and related to mobile devices. As more confidential data gets routed through and stored on these increasingly powerful units, proper multi-tiered security protocols will become increasingly important.
We may laugh at Ms. Hilton now, but her experience shows us how important it is to implement security practices and processes that account for the technical ineptitude of the end user.
Carmi Levy
http://writteninc.blogspot.com
Is this a different hacker than Nick Jacobson, who broke into T-Mobile's system and stole photos from Paris Hilton, Nicole Richie, Demi Moore, Ashton Kutcher, etc.? That was all on Slashdot a month ago. Articles about that particular hack follow:
http://www.securityfocus.com/news/10271
http://www.infosecinstitute.com/blog/ethical_hacking_computer_forensics.html
I wonder how long it was till she blew chunks, after she scarfed that McD's down.
some those pictures are HAWT. why couldn't she have taken them on hi-res?
"Everybody keeps blaming TMobile When.. IF there WAS hacking going on.. it's Dangers fault.."
That is so irrelevant. Her contract is with T-Mobile. You as a customer don't care who they source their services from, or if they did due dilligence on Danger's systems before selling it to you. You are paying your fees to T-Mobile.
If you saw the first site you shoulda scroleld to the bottom and noticed it said
"The previous information was obtained using social engineering tactics."
Soecial Engineering wouldn't be the fault of T-Mobile.
Well said Slaven.
If T-Mo was dumb enough to sign up with Danger and not require that they put some sort of memory card in their SK then its T-Mo fault that she got screwed. Her payments went to T-Mo not Danger. I wouldn't touch T-Mo with a ten foot pole.
http://www.joeytdog.com/gallery/getmore
mirror -- camphone images (unbranded)
I'm guessing non of yall have a sidekick? danger handles the sk data which is 20 dollars a month which danger does get. they handle all of that. tmobile handles the phone feature.. as us sidekick users we did overlook danger sceurity.. so did tmobile.. even danger themself thought it was hack free but we see that they are wrong
i'm sure that T-mobile is going to burn for this...
i just found an intresting thing from Kevinrose.com it seems that its really easy to hack t-mobile voicemail. all you have to do is use a type of caller ID.
i wount spoil it for you just go to http://www.kevinrose.com/index.php/weblog/comments/202/
and read the whole thing. its very intresting
p.s. does anyone know any other small hacks like this?
i'm sure that T-mobile is going to burn for this...
i just found an intresting thing from Kevinrose.com it seems that its really easy to hack t-mobile voicemail. all you have to do is use a type of caller ID.
i wount spoil it for you just go to http://www.kevinrose.com/index.php/weblog/comments/202/
and read the whole thing. its very intresting
p.s. does anyone know any other small hacks like this?
The pictures are just too perfect, looks like a stylist and a photographer were always around. Would stick with the publicity version too
kofein_machine, i fully agree some pics looks too good to be true. It could be however, that they are actually professionnal quality pictures gathered with low-res personal shots in the picture book.
Anyway there's another thing i just don't get. Why is T-Mobile actually reacting? I mean, making such an announcement implicitely means that disclosed data actually came from the user's personal account. Would they say so just to cover themselves from just any "MS windows level" security flaw? Would they say so without checking first? And then again, are they entitled to check someone's personal data?
On the other hand, making no announcement at all could have been understood either way : they checked and found no reason to make a deal out of what would obviously be a fraud; or the security flaw is just to huge/obvious/embarassing for them to comment.
Commenting the event the way they did sounds weird to me.
Shes not that intelligent. Someone (like anyone) who knows her cell phone number could easily just start plugging in names for passwords, like: hilton, her cats name, the last porn she was in, etc.
Its not that difficult..
Screw T-Mo and Danger, lets stick to the important stuff here. Who is the girl she is kissing? Why does that girl while kissing Paris look like she has man-hands?
Does everybody have short term memory loss? Does anybody remember past 2 weeks ago? I think it's pretty obvious how it happened... Look at this previous Engadget article:
http://engadget.com/entry/1234000777027113/
T-Mo, Danger, it doesn't matter.
DON'T TRUST YOUR PERSONAL DATA TO TELECOM SCHMOES!!!!
How much you want to bet her password was "tinkerbell" Searously, I'm not kidding I would put good money on it.
Paris Hilton want to beat Britney Spears over google, I bet. Looking up on google. Paris get 3.8 millions while Britney got 7.8 millions. In images.google.com, there is 11.2 thousands for Paris and 109 thousands for Britney.
Keep up, Paris! You can beat that bitch! Bwhahaha
Hey, at least now we *all* have Christ's personal email address. (I can't believe that --- He would only gave me His work email!)
YEA I LISTNED TO THOSE PRANK CALLS WITH THE AUSSIE GUY THEY DEFFENTLY SOUND FAKE...I BEEN LOOKIN THROUGH THEM NUMBERS ALSO I WONDER IF THERES ANYONE WHO HASNT CHANGED THERE NUMBER
EMINEM CHANGED HIS NUMBER...*STARTS TO CRY*....DAMN I WUZZ GONNA BE THE SECOND BEST WHITE RAPPER...
(Cough!) Who do you think is number one Teenmutant(#32)? Vanilla Ice?
As a previous T-Mobile employee who dealt with sidekicks on a
daily basis, i can assure you, the network is secure. Even an employee cannot
access pictures or contacts or emails from the sidekick servers, at least not
from work. They do not have access to the passwords, either. Most likely, Paris
let her sidekick fall into the wrong hands, or let her password slip.
I have an account with T-mobile, and i have never been happier with any other
cell phone service. I can assure you, T-Mobile has your total security as a
priority, and I recommend them for all your mobile needs!!!
it was easty for this "hacker" to get into her system. he didnt even hack anything. all he had to do was to go online, try to log in, choose "i forgot my password" and answer one simple question: "What is my dog's name"
Gee, cuz that's not hard to figure out or anything
http://www.engadget.com/entry/1234000547032961/
hey paris sorry to hear that ur pager have been hacked. i havent talked to u for long time and ive suprisin ure algready added my email in ur sk2. hopefully u coulda email me back ;-D Dmitri Korolev
stoneyhracer@yahoo.com
Maybe her house/life is SO BUGGED (like in the movie "Sliver") that no password goes un-stolen.
Eban
How much you want to bet her password was "tinkerbell" Searously, I'm not kidding I would put good money on it.
it can't be tinkerbell has to be something else.
What is your favorite pet's name?
anyone know the answer to that gets a prize...
Eban
How much you want to bet her password was "tinkerbell" Searously, I'm not kidding I would put good money on it.
it can't be tinkerbell has to be something else.
What is your favorite pet's name?
anyone know the answer to that gets a prize...
omg...how stupid... shes posing in every one of her shots, even the photoshop'd 'head on boobyBabe' photos. What pathetic lamer spends so much time gazing at their dopey/druggy-eyed selves? This is a NON EVENT people, count the media sucked in (and dragging us down with it all...)
Who is the girl that Paris is kissing in the pictures taken from her TMobile Sidekick?
This is a perfect storm of incidents.1
1)Paris lost her sidekick at a party. If it had power, the thief could access this stuff all day long
2)Paris's phone number etc. was posted by the hacker or he gave it out.
3)The hackers didn't hack anything I bet-they had her phone number and email address from the above hack. ParisHilton@tmail.com or something like that. Both data points are PUBLIC DOMAIN
4)The only security to prevent a user from getting data is the PASSWORD. This is at the web portal backup. Everyone can hack on that all day long.
5)Forget the password-they probably bypassed that since the "I forgot my password" page asks you to choose from 5 EZ questions. Questions that any reader of People Magazine knows.
6) Tmobile asks for the public domain number and the "password"at the My T-Mobile login-real secure.
7)TMobiles database in general is WIDE OPEN and has been hacked, and has not be resolved yet.
So, yes, Danger hosts the data but T-Mobile is the portal that let them in because they are just a DUM phone company wih no experience in webmail security
They have the full uncensored address book online here:
http://paris.clickstuff.com/
BTW, it has just been revealed who the hacker accessed her account:
Paris' security question: "What's your pet's name?"
Paris' secret answer: "Tinkerbell"
Doh!
lol...
I CANT belive they talk about this insident like it would be some real hacking. I have done it & i belive every one can do it whit basic computer knolage & social engineering .
Things like that happen all the time, only differents is that most of us are not so lame that we start to post it all ower the internet.
I have a lot more then pic, all the emails, videos & more nude pic lol, this dosent mean that i will post it now all ower the internet lol
Britney, Eminem, Christina... & others lol, all them should shange theyr passwords & even more important: password Q:/A: ;) :P
"Social Engineering - Because There Is No Patch For Human Stupidity"
I dont think that it is Paris's fault for somebody hacking into her sidekick. It is these stupid people around the world. Why does this kind of stuff always happen to Paris? Honestly people... you should leave her alone for a change.
46: Q: Why does this kind of stuff always happen to Paris?
A: Maybe because she is big embarrassment for Hilton family, she is one of the most ignorant celebrities out there & WHY NOT?
One thing more, It's not JUST HER :)
I have a Sidekick2. As far as the Paris Hilton situation all she had to do was drop her phone or leave it with any individual and they couldve gotten her password. In every my T-mobile when u sign in and u forgot your password they ask you to type your celluar # and then they automatically send your password to your phone via text message. Which this process only takes about 30 seconds. This was how Paris Hilton's Sidekick2 was hacked. Any human with half a brain can figure this process out. You dont need to be a special computer hacker or genius. All you need is to be able to read.
Name: Paris Hilton
Password: Tinkerbell
I think it fucking hilarious that someone hacked her. if I could hack into to anyones phone it would be hers u know she's probally got some nude kinky pics on her phone so that's why its cool that they hacked into her shit!
The Links to the Paris Hilton video are the only reason that Paris is even so popular now. At least she can act like she gives a damn. The movie has sold like over a million copies at the Paris Hilton site.
The Links to the Paris Hilton video are the only reason that Paris is even so popular now. At least she can act like she gives a damn. The movie has sold like over a million copies at the Paris Hilton site.
i fully agree some pics looks too good to be true. It could be however, that they are actually professionnal quality pictures gathered with low-res personal shots in the picture book.
Anyway there's another thing i just don't get. Why is T-Mobile actually reacting? I mean, making such an announcement implicitely means that disclosed data actually came from the user's personal account. Would they say so just to cover themselves from just any "MS windows level" security flaw? Would they say so without checking first? And then again, are they entitled to check someone's personal data?
On the other hand, making no announcement at all could have been understood either way : they checked and found no reason to make a deal out of what would obviously be a fraud; or the security flaw is just to huge/obvious/embarassing for them to comment.
Commenting the event the way they did sounds weird to me.
The Links to the Paris Hilton video are the only reason that Paris is even so popular now. At least she can act like she gives a damn. The movie has sold like over a million copies at the Paris Hilton site.
I think it fucking hilarious that someone hacked her. if I could hack into to anyones phone it would be hers u know she's probally got some nude kinky pics on her phone so that's why its cool that they hacked into her shit!
i have a Sidekick2. As far as the Paris Hilton situation all she had to do was drop her phone or leave it with any individual and they couldve gotten her password. In every my T-mobile when u sign in and u forgot your password they ask you to type your celluar # and then they automatically send your password to your phone via text message. Which this process only takes about 30 seconds. This was how Paris Hilton's Sidekick2 was hacked. Any human with half a brain can figure this process out. You dont need to be a special computer hacker or genius. All you need is to be able to read.