Skip to content
TopicTracker
From HackerNewsView original
TranslationTranslation

You can see T-Mobile's acquisitions by where its logins are hosted

The article examines T-Mobile's acquisition history by analyzing where its login pages are hosted, showing how mergers with companies like Sprint and MetroPCS led to different authentication systems and URLs still in use.

Background

- T-Mobile US is one of the three major US wireless carriers. It has grown aggressively through acquisitions — most notably Sprint (2020) — plus mergers with MetroPCS and UScellular assets, and purchases of Layer3 TV, Mint Mobile, and Ultra Mobile. - The article argues that T-Mobile's login/authentication pages reveal its acquisition history. Instead of a single unified login, T-Mobile runs separate, rebranded identity providers for each acquired brand, with distinct domain names and infrastructure. - This matters because it shows the fragmented state of T-Mobile's internal systems years after the "merger" was supposedly completed. For security researchers and customers, it raises practical concerns: inconsistent security postures, confusing credential management, and a larger attack surface. - Prior context: Sprint's own pre-merger brand sprawl (Boost, Virgin Mobile, Ting) was folded in but not unified. T-Mobile has publicly promised network integration, but this analysis uses observable HTTP redirects and authentication endpoints — not internal documents — to illustrate how incomplete that integration actually is.