Live data from Hacker News

SIM swap horror story: I've lost decades of data and Google won't help

zdnet.com

21–30 of 303 posts

Re: SIM swap horror story: I've lost decades of data and Google won't help

#21

Earlier quoted context omitted.

Thanks for reminding me... again... about this. Why haven't I backed up my gmail data yet? It has been years since I realized I have to do it. Why haven't I done it?

Because it's not easy to automate.

Gmail alone is easy - use POP in a mail client, set it to mark stuff read, leave it on the server etc https://support.google.com/mail/answer/7104828?hl=en

Re: SIM swap horror story: I've lost decades of data and Google won't help

#22

I believe Google has some kind of service you can turn on where you will pair it with a U2F token like a Yubikey or their Titan key. At that point, all other forms of login and password recovery are turned off. In theory, that should stop the SIM-swap attack. See: https://support.google.com/accounts/answer/7539956?hl=en

Unfortunately, Yubikey at least basically only works in Google Chrome, so if you actually want to use your account you have to use methods other than the Yubikey.

You can use it in any browser. You have to register it in chrome. Crappy, but not a line in the sand I'm willing to die on.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#23
post #10

I certainly didn't appreciate how much SIM cards are the keys to our modern lives until mine got stolen. Interestingly, my thieves took a different tack: they actually stole the physical SIM card! You might ask how this could happen: I was traveling internationally and had a friendly guy at an official kiosk in the Heathrow arrivals hall swap out my SIM card for a local SIM. He palmed my SIM and gave me back a dud wi…

> Interestingly Heathrow police didn't care as the "theft" was only a $5 SIM card and not a "high enough value item" to warrant investigation.

What about the part that's "being a part of a criminal conspiracy to steal $40k?" I guess that's not something for the airport police to deal with though.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#24

Recently I discovered that Facebook has a policy that no one with pending misdemeanors can be hired if they are just a contractor. We recently had to turn away a 23 year old combat veteran who had deployed to Afghanistan because he had a pending Class C misdemeanor. That’s a max fine of $50 for the state this was in. All for a $16.50 an hour job. The amount of indifference to suffering by people in the corporate worl…

Are you sure you are commenting in the right thread?

Re: SIM swap horror story: I've lost decades of data and Google won't help

#26
post #11

Is there some mobile provider that has a way higher standard of security? Something like "Cloudflare for SIM"

No.

The issue is partially that while social engineering countermeasures that could help prevent sim swaps could be helped by better training and more rigorous security checks, there are actually bad actors who are employees of the carriers who can be paid off to switch SIMs.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#28
post #12

Anyone who wants to defend themselves, consider using U2F where you can and Google Advanced Protection. I just recently picked up a bluetooth security key because one is needed to log an iPhone into an account using advanced protection; there is no SMS backup loophole. The Titan key bundle comes with a bluetooth and USB key, which is enough to get started, though frankly you probably want a couple additional backup k…

Why doesn't Google get rid of SMS recovery completely? It's a huge security flaw that can be easily exploited.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#29
post #12

Anyone who wants to defend themselves, consider using U2F where you can and Google Advanced Protection. I just recently picked up a bluetooth security key because one is needed to log an iPhone into an account using advanced protection; there is no SMS backup loophole. The Titan key bundle comes with a bluetooth and USB key, which is enough to get started, though frankly you probably want a couple additional backup k…

U2F keys are great but I look forward to the day when they’re more widely available outside the US. And I’m still waiting for my replacement from Feitian for the recent vulnerability. Not to say you shouldn’t use them, but... they have their limits. Particularly Advanced Protection which forces you to use Google’s browser in many situations and disables API access so I can’t use the API to get my own data, only Google’s official apps and a small exception for Apple’s.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#30
post #8

The industry needs to learn that sms 2fa is not secure because getting a sim for someone else is so easy. And this happening in every country.

I would say that for the average user sms 2FA is secure enough.

P.S. I might have a different perspective as where i am from, there really aren't important services (banks etc.) that are using sms 2FA. Mobile operators doesn't ship SIM cards over mail, you can get a new SIM only in person providing ID (or PIN/PUK in case of prepaid cards). Probably my country is just too small market for these kind of attacks so i feel secure enough when using sms 2FA.

Post reply on HN