Live data from Hacker News

SIM swap horror story: I've lost decades of data and Google won't help

zdnet.com

61–70 of 303 posts

Re: SIM swap horror story: I've lost decades of data and Google won't help

#61
post #33
post #12

Anyone who wants to defend themselves, consider using U2F where you can and Google Advanced Protection. I just recently picked up a bluetooth security key because one is needed to log an iPhone into an account using advanced protection; there is no SMS backup loophole. The Titan key bundle comes with a bluetooth and USB key, which is enough to get started, though frankly you probably want a couple additional backup k…

Why not "defend" yourself by not relying on gmail? It's not exactly the first time this has happened.

Absolutely, if you want. I am not advocating to use or not use Gmail or other services. But also be sure to use U2F on whatever you can, be it Fastmail or Proton Mail or what have you. I think Proton Mail is still working on their U2F support today, though.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#62

A few suggestions: 1) Call your cellphone carrier and ask to set up a password/PIN to be used for when you call into the customer service phone number. 2) Consider your phone number and SIM card insecure. The phone carriers are ignoring the SIM swap problem even though they know how much damage it's causing. Give your phone number to as few companies as possible. Phone services such as Google Voice work without a SIM…

> Call your cellphone carrier and ask to set up a password/PIN to be used for when you call into the customer service phone number.

What is really infuriating is that it is not required for BestBuy-type authorized resellers that hook directly into the system.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#63
post #4

This is a good place to remind everyone of Google Takeout [1]. Back up all of your data. Don't let this horror story happen to you. [1] https://takeout.google.com/settings/takeout

My previous experience (years ago) was that it actually gave me incomplete backups... which is.. insane and frustrating. Hopefully that’s fixed now.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#64

Earlier quoted context omitted.

I think the common wisdom dictates that since we aren't paying, we aren't the actual customers. I'll bet advertisers have great customer service.

That's less common wisdom and more of a catchy but dumb meme. There are all sorts of things you can buy that have crappy-to-nonexistent customer service.

Sure, but even Comcast isn't as bad as Google; not as much depends on Comcast, and Google has mountains of p[eople's key life-altering data, yet it is nearly impossible to speak with a human that has any capability to effect a change.

As with every generalizations, there are exceptions, but they generally only prove the rule.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#65
post #43

Earlier quoted context omitted.

It wasn't secure enough for the author of this article.

Not really an average person isn't he?

How is he not an average person, as far as security goes?

1) he didn't use a password app

2) he thought google drive was a safe place for his stuff

3) he thought google drive was a secure place for his stuff

All three things, which I would bet are fairly common assumptions (the last 2 are certainly part of Google's marketing!), turned out to bite him.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#66
post #43

Earlier quoted context omitted.

It wasn't secure enough for the author of this article.

Not really an average person isn't he?

Before the identity theft occurred, what about the the author made him particularly "not average"? Being an early twitter adopter or something?

Re: SIM swap horror story: I've lost decades of data and Google won't help

#67
post #30
post #8

The industry needs to learn that sms 2fa is not secure because getting a sim for someone else is so easy. And this happening in every country.

I would say that for the average user sms 2FA is secure enough. P.S. I might have a different perspective as where i am from, there really aren't important services (banks etc.) that are using sms 2FA. Mobile operators doesn't ship SIM cards over mail, you can get a new SIM only in person providing ID (or PIN/PUK in case of prepaid cards). Probably my country is just too small market for these kind of attacks so i fe…

Bank of America uses SMS.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#68
post #42
post #23

Earlier quoted context omitted.

> Interestingly Heathrow police didn't care as the "theft" was only a $5 SIM card and not a "high enough value item" to warrant investigation. What about the part that's "being a part of a criminal conspiracy to steal $40k?" I guess that's not something for the airport police to deal with though.

Ayup. Here's what I got back from them: In light of the extended Fraud on your account, I believe that due to the 7 day lapse between you collecting the SIM and returning to the USA, then your details could have been compromised anywhere. In all probability, this occurred in the USA as this is where the accounts have been set up and believed the fraudsters would have had to have been in order to benefit from the crim…

I understand your frustration, but I also think they have a point.

What you're telling us is all based on your educated guesses as to how they might have pulled this. There are things that feel a bit weird and I'm guessing you have no evidence to prove them, such as the scammer shipping the real SIM back to Atlanta in time before you realise the issue.

How did you realise the SIM card you were handed was fake? Couldn't it be that they instead duplicated your SIM whilst you weren't looking?

IMHO the police (or FBI or whatevs) in the US should conduct the investigation as that's were the fraud happened. They'll evaluate if it's worth it contacting their counterparts in the UK to move forward. However I also think it is good that you've given a heads up to the UK local authorities.

Do you remember what company was offering the local SIMs? I've seen mostly Lebara, but not in Heathrow...

Re: SIM swap horror story: I've lost decades of data and Google won't help

#69
post #8

The industry needs to learn that sms 2fa is not secure because getting a sim for someone else is so easy. And this happening in every country.

In times like these, I am glad to live in a stone age country like German, where it is near-impossible to get a new SIM without going to the store in person and presenting a government-issued ID.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#70
post #10

I certainly didn't appreciate how much SIM cards are the keys to our modern lives until mine got stolen. Interestingly, my thieves took a different tack: they actually stole the physical SIM card! You might ask how this could happen: I was traveling internationally and had a friendly guy at an official kiosk in the Heathrow arrivals hall swap out my SIM card for a local SIM. He palmed my SIM and gave me back a dud wi…

fun fact about sims. they run a java operating system which can be accessed via binary SMS messages (apdu messages) - invisible to your phone, with the right sim pin, they can get filesystem access in this 'os' and steal your private keys and phone identification numbers, effectively allowing them to mitm / clone your phone and calls/sms etc.

that being said it's just plain silly how important these crummy devices are, and how little information and warnings they come with.

set a good sim pin, that will save u from this type of trouble. of course, it won't save u from physical phone / sim access.

Post reply on HN