Anyone who wants to defend themselves, consider using U2F where you can and Google Advanced Protection. I just recently picked up a bluetooth security key because one is needed to log an iPhone into an account using advanced protection; there is no SMS backup loophole. The Titan key bundle comes with a bluetooth and USB key, which is enough to get started, though frankly you probably want a couple additional backup k…
Why doesn't Google get rid of SMS recovery completely? It's a huge security flaw that can be easily exploited.
SIM swap horror story: I've lost decades of data and Google won't help
51–60 of 303 posts
Re: SIM swap horror story: I've lost decades of data and Google won't help
#52My solution to all of it is literally just 2 emails. Both 2fa. Recovery exists but the numbers and emails are unknown to the world beyond Google or m$ servers. And those don't get used to register anything ever. I park my recoveries then use my main email as my most public one. Everything else is registered and recoverable on the second email that also isn't publicly known unless one of the services I'm attached to gets their data leaked etc etc etc....so even if they did successfully swap my SIM they can't get anything else.
TMobile got hacked a few months back and around the same time my personal debit card that stayed in my wallet the whole time and I don't ever use in public literally for that reason. Got charged. They tried to empty it all. I pressed and pressed the only thing they could do for me was ask for a specific code. Verbal 2fa. I think if I remember correctly none of the data showed up publicly anywhere yet not sure about the specific incident I just thought the timing was weird.
If that's the best security TMobile has and that's all their customer support has to offer us. They have failed as a company in my eyes. And it will only get worse not better as more middle managers get their cut of the security upgrades that they will partially and incorrectly implement.
Of course they won't lift a finger your not a Kardashian
Re: SIM swap horror story: I've lost decades of data and Google won't help
#53The fact that ACH is slow is a feature not a bug. Remember that when people want to speed up money transfers. > After a couple of days, our bank reversed the $25,000 charge and told us that the fraud department caught the ACH withdrawal before it was fully processed so that neither my family nor the bank lost this money forever.
Mobile phone numbers shouldn't be used as a second factor, much less as a way to fully recover online credentials to your bank account.
Re: SIM swap horror story: I've lost decades of data and Google won't help
#54Earlier quoted context omitted.
I think the common wisdom dictates that since we aren't paying, we aren't the actual customers. I'll bet advertisers have great customer service.
That's less common wisdom and more of a catchy but dumb meme. There are all sorts of things you can buy that have crappy-to-nonexistent customer service.
But that doesn't contradict the point of the comment you were replying to, does it?
Edit: You should reply instead of just downvoting.
Re: SIM swap horror story: I've lost decades of data and Google won't help
#55This is a good place to remind everyone of Google Takeout [1]. Back up all of your data. Don't let this horror story happen to you. [1] https://takeout.google.com/settings/takeout
Thanks for reminding me... again... about this. Why haven't I backed up my gmail data yet? It has been years since I realized I have to do it. Why haven't I done it?
Re: SIM swap horror story: I've lost decades of data and Google won't help
#56This is why I don't use Google for anything of importance. No customer support = I am not using it for anything of importance. Consider it a 'burner' service.
Re: SIM swap horror story: I've lost decades of data and Google won't help
#57A few suggestions: 1) Call your cellphone carrier and ask to set up a password/PIN to be used for when you call into the customer service phone number. 2) Consider your phone number and SIM card insecure. The phone carriers are ignoring the SIM swap problem even though they know how much damage it's causing. Give your phone number to as few companies as possible. Phone services such as Google Voice work without a SIM…
Note that, at least for TMobile, AT&T, and Verizon, the password/PIN is presented to the CSR in plaintext (as they verify the pin over the phone verbally).
I'd assumed they'd transfer to some pin-capture applet to verify, but nope.
> Use an authentication app, such as Google Authenticator
If you decide on Google Authenticator, make sure you scan the barcode with 2 devices (say, your tablet and your phone) to back up that credential. Or just use Authy.
Re: SIM swap horror story: I've lost decades of data and Google won't help
#58Earlier quoted context omitted.
Unfortunately, Yubikey at least basically only works in Google Chrome, so if you actually want to use your account you have to use methods other than the Yubikey.
You can use it in any browser. You have to register it in chrome. Crappy, but not a line in the sand I'm willing to die on.
The insistence on using Chrome is arbitrary and I don't like it. The use of U2F rather than WebAuthn at least has a technical justification (older Android devices can't do WebAuthn, and while it's backward compatible in the sense that you can use a WebAuthn authentication having signed up with U2F, vice versa is not possible, so old Android devices would have a confusing UX behaviour) but the insistence on Chrome is just arbitrary lock-in.
I won't be dying on that hill either, but it does suck.
Re: SIM swap horror story: I've lost decades of data and Google won't help
#59The industry needs to learn that sms 2fa is not secure because getting a sim for someone else is so easy. And this happening in every country.
The problem is SMS account recovery, which is a really bad idea.
Re: SIM swap horror story: I've lost decades of data and Google won't help
#60Earlier quoted context omitted.
Why doesn't Google get rid of SMS recovery completely? It's a huge security flaw that can be easily exploited.
Probably because the more barriers you put in the way of scams, social engineering, etc. the harder you make it for people to legitimately get back into their accounts and the more likely it is that you'll instead read stories about how someone "forgot their credentials and lost access to everything in their account and Google won't do anything about it." No opinion on SMS specifically but there are tradeoffs.