Live data from Hacker News

SIM swap horror story: I've lost decades of data and Google won't help

zdnet.com

51–60 of 303 posts

Re: SIM swap horror story: I've lost decades of data and Google won't help

#51
post #28
post #12

Anyone who wants to defend themselves, consider using U2F where you can and Google Advanced Protection. I just recently picked up a bluetooth security key because one is needed to log an iPhone into an account using advanced protection; there is no SMS backup loophole. The Titan key bundle comes with a bluetooth and USB key, which is enough to get started, though frankly you probably want a couple additional backup k…

Why doesn't Google get rid of SMS recovery completely? It's a huge security flaw that can be easily exploited.

It depends on your threat level. If you're just trying to avoid phishing, it's great, something like 99.9% effective. However, if you're worried you'll be targeted, where someone will go through the effort to do this to you specifically, then it's not a good choice.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#52
Since becoming aware of my own problems with google (they truly could care less about their users data) and reading stories about previous incidents of swapping SIM cards.

My solution to all of it is literally just 2 emails. Both 2fa. Recovery exists but the numbers and emails are unknown to the world beyond Google or m$ servers. And those don't get used to register anything ever. I park my recoveries then use my main email as my most public one. Everything else is registered and recoverable on the second email that also isn't publicly known unless one of the services I'm attached to gets their data leaked etc etc etc....so even if they did successfully swap my SIM they can't get anything else.

TMobile got hacked a few months back and around the same time my personal debit card that stayed in my wallet the whole time and I don't ever use in public literally for that reason. Got charged. They tried to empty it all. I pressed and pressed the only thing they could do for me was ask for a specific code. Verbal 2fa. I think if I remember correctly none of the data showed up publicly anywhere yet not sure about the specific incident I just thought the timing was weird.

If that's the best security TMobile has and that's all their customer support has to offer us. They have failed as a company in my eyes. And it will only get worse not better as more middle managers get their cut of the security upgrades that they will partially and incorrectly implement.

Of course they won't lift a finger your not a Kardashian

Re: SIM swap horror story: I've lost decades of data and Google won't help

#53
post #31

The fact that ACH is slow is a feature not a bug. Remember that when people want to speed up money transfers. > After a couple of days, our bank reversed the $25,000 charge and told us that the fraud department caught the ACH withdrawal before it was fully processed so that neither my family nor the bank lost this money forever.

Instant transfers work fine in countries where banks do their job properly.

Mobile phone numbers shouldn't be used as a second factor, much less as a way to fully recover online credentials to your bank account.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#54

Earlier quoted context omitted.

I think the common wisdom dictates that since we aren't paying, we aren't the actual customers. I'll bet advertisers have great customer service.

That's less common wisdom and more of a catchy but dumb meme. There are all sorts of things you can buy that have crappy-to-nonexistent customer service.

> There are all sorts of things you can buy that have crappy-to-nonexistent customer service.

But that doesn't contradict the point of the comment you were replying to, does it?

Edit: You should reply instead of just downvoting.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#55
post #4

This is a good place to remind everyone of Google Takeout [1]. Back up all of your data. Don't let this horror story happen to you. [1] https://takeout.google.com/settings/takeout

Thanks for reminding me... again... about this. Why haven't I backed up my gmail data yet? It has been years since I realized I have to do it. Why haven't I done it?

Check out Mailstore Home

Re: SIM swap horror story: I've lost decades of data and Google won't help

#57

A few suggestions: 1) Call your cellphone carrier and ask to set up a password/PIN to be used for when you call into the customer service phone number. 2) Consider your phone number and SIM card insecure. The phone carriers are ignoring the SIM swap problem even though they know how much damage it's causing. Give your phone number to as few companies as possible. Phone services such as Google Voice work without a SIM…

> Call your cellphone carrier and ask to set up a password/PIN

Note that, at least for TMobile, AT&T, and Verizon, the password/PIN is presented to the CSR in plaintext (as they verify the pin over the phone verbally).

I'd assumed they'd transfer to some pin-capture applet to verify, but nope.

> Use an authentication app, such as Google Authenticator

If you decide on Google Authenticator, make sure you scan the barcode with 2 devices (say, your tablet and your phone) to back up that credential. Or just use Authy.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#58
post #22

Earlier quoted context omitted.

Unfortunately, Yubikey at least basically only works in Google Chrome, so if you actually want to use your account you have to use methods other than the Yubikey.

You can use it in any browser. You have to register it in chrome. Crappy, but not a line in the sand I'm willing to die on.

Conventionally, one metaphorically chooses a _hill_ to die on, and lines in the sand are only crossed or redrawn, not died on.

The insistence on using Chrome is arbitrary and I don't like it. The use of U2F rather than WebAuthn at least has a technical justification (older Android devices can't do WebAuthn, and while it's backward compatible in the sense that you can use a WebAuthn authentication having signed up with U2F, vice versa is not possible, so old Android devices would have a confusing UX behaviour) but the insistence on Chrome is just arbitrary lock-in.

I won't be dying on that hill either, but it does suck.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#59
post #8

The industry needs to learn that sms 2fa is not secure because getting a sim for someone else is so easy. And this happening in every country.

SMS 2FA is fine. 2FA adds another layer on top of your password. The second factor doesn’t have to be particularly secure to make you safer.

The problem is SMS account recovery, which is a really bad idea.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#60
post #38
post #28

Earlier quoted context omitted.

Why doesn't Google get rid of SMS recovery completely? It's a huge security flaw that can be easily exploited.

Probably because the more barriers you put in the way of scams, social engineering, etc. the harder you make it for people to legitimately get back into their accounts and the more likely it is that you'll instead read stories about how someone "forgot their credentials and lost access to everything in their account and Google won't do anything about it." No opinion on SMS specifically but there are tradeoffs.

It would be more just if people losing access to their accounts were those that lost their credentials rather than anyone that has a SMS number tied to their account. Other approaches to account recovery could be explored but none of them should involve SMS.
Post reply on HN