Live data from Hacker News

SIM swap horror story: I've lost decades of data and Google won't help

zdnet.com

41–50 of 303 posts

Re: SIM swap horror story: I've lost decades of data and Google won't help

#41

A few suggestions: 1) Call your cellphone carrier and ask to set up a password/PIN to be used for when you call into the customer service phone number. 2) Consider your phone number and SIM card insecure. The phone carriers are ignoring the SIM swap problem even though they know how much damage it's causing. Give your phone number to as few companies as possible. Phone services such as Google Voice work without a SIM…

> 4) You can retake possession of your hacked Gmail account by providing one of the previously used passwords. No need to have a working phone.

That's possible?! I only ever change password if I suspect it might have been compromised. Now if a service allows to use old passwords, that's quite a bummer and makes password change meaningless.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#42
post #23
post #10

I certainly didn't appreciate how much SIM cards are the keys to our modern lives until mine got stolen. Interestingly, my thieves took a different tack: they actually stole the physical SIM card! You might ask how this could happen: I was traveling internationally and had a friendly guy at an official kiosk in the Heathrow arrivals hall swap out my SIM card for a local SIM. He palmed my SIM and gave me back a dud wi…

> Interestingly Heathrow police didn't care as the "theft" was only a $5 SIM card and not a "high enough value item" to warrant investigation. What about the part that's "being a part of a criminal conspiracy to steal $40k?" I guess that's not something for the airport police to deal with though.

Ayup. Here's what I got back from them:

    In light of the extended Fraud on your account, I believe
    that due to the 7 day lapse between you collecting the SIM
    and returning to the USA, then your details could have been
    compromised anywhere. In all probability, this occurred in
    the USA as this is where the accounts have been set up and 
    believed the fraudsters would have had to have been in order
    to benefit from the crime.
 
    The fact that you bought a SIM card in the UK is purely
    circumstantial I’m afraid, therefore we would not 
    investigate this further.
Of course I was shouting "THEY HAD TO SHIP IT BACK TO THE U.S. FOR IT TO WORK" as well as providing the call logs documenting calls from the Atlanta region (where I don't live and hadn't visited), but it fell on deaf ears and I gave up. That response made me feel like a tin-hatted conspiracy theorist, though: yes, I am certain I was defrauded through an international criminal conspiracy.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#43
post #30

Earlier quoted context omitted.

I would say that for the average user sms 2FA is secure enough. P.S. I might have a different perspective as where i am from, there really aren't important services (banks etc.) that are using sms 2FA. Mobile operators doesn't ship SIM cards over mail, you can get a new SIM only in person providing ID (or PIN/PUK in case of prepaid cards). Probably my country is just too small market for these kind of attacks so i fe…

It wasn't secure enough for the author of this article.

Not really an average person isn't he?

Re: SIM swap horror story: I've lost decades of data and Google won't help

#44
post #11

Is there some mobile provider that has a way higher standard of security? Something like "Cloudflare for SIM"

I noticed that author assumed he couldn't call 611 and took how long to contact via alternate phones.

I'm pretty sure 611 works without a SIM card.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#46

Earlier quoted context omitted.

I think the common wisdom dictates that since we aren't paying, we aren't the actual customers. I'll bet advertisers have great customer service.

That's less common wisdom and more of a catchy but dumb meme. There are all sorts of things you can buy that have crappy-to-nonexistent customer service.

I think there can be several reasons that a company lacks good customer service. One might be lack of competition. Another could be that they don't see their users as customers.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#47
post #4

This is a good place to remind everyone of Google Takeout [1]. Back up all of your data. Don't let this horror story happen to you. [1] https://takeout.google.com/settings/takeout

Thanks for the reminder--I've done it several times in the past, but it wasn't a scheduled thing at all.

There's a new checkbox in takeout that lets you schedule a backup every 2 months (and then presumably you'll get an email when you need to download it).

Does anyone else have issues with takeout failing with "unknown error occurred" if you use the default of selecting all products? I have to manually create multiple takeout archives (one for gmail, one for photos, one for location history...)

Re: SIM swap horror story: I've lost decades of data and Google won't help

#48
This is why I would like to trust my digital identity to my bank.

They have enough local, physical presence so that I could show up in person and prove who I am. Also the personnel is already familiar with checking the identity and hopefully less suspectiple to social engineering.

2FA tokens and codesheets without SMS backup are secure, but bit tricky to manage. Takes some effort to distribute to different, secure places (think if house burns) and some regular checks to verify backup tokens are alive and codesheets not lost.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#49
Unlike what the OP stated, the key is NOT to list you phone number as an SMS 2FA recovery option. Only use the non-SMS options (e.g. app-based recovery, Google Authenticator, recovery codes). Adding SMS as an option makes your account less secure, not more.

Unfortunately, most sites do not allow you to turn off SMS recovery even if they offer other 2FA options.

Security is only as strong as the weakest link, and SMS is very weak.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#50
post #12

Anyone who wants to defend themselves, consider using U2F where you can and Google Advanced Protection. I just recently picked up a bluetooth security key because one is needed to log an iPhone into an account using advanced protection; there is no SMS backup loophole. The Titan key bundle comes with a bluetooth and USB key, which is enough to get started, though frankly you probably want a couple additional backup k…

U2F keys are great but I look forward to the day when they’re more widely available outside the US. And I’m still waiting for my replacement from Feitian for the recent vulnerability. Not to say you shouldn’t use them, but... they have their limits. Particularly Advanced Protection which forces you to use Google’s browser in many situations and disables API access so I can’t use the API to get my own data, only Googl…

Yeah, Chromium is needed to add keys, which effectively means you can’t enable Advanced Protection without Chromium. I personally ran into this wall. I acknowledge that this sucks, as a person that intentionally only uses Firefox, but to be clear logging in and most other operations work absolutely fine with Advanced Protection.

Does it really disable all API access? I thought it only blocked certain OAuth scopes, but to be honest I haven’t really tried.

I was able to login to a NVIDIA Shield, but only by resetting and bootstrapping off a spare Android device (!!!) because U2F keys are broken on Shield. Interestingly, my Samsung TV remains signed into Youtube, which is kind of odd now that I think about it.

Post reply on HN