Live data from Hacker News

SIM swap horror story: I've lost decades of data and Google won't help

zdnet.com

71–80 of 303 posts

Re: SIM swap horror story: I've lost decades of data and Google won't help

#72
post #49

Unlike what the OP stated, the key is NOT to list you phone number as an SMS 2FA recovery option. Only use the non-SMS options (e.g. app-based recovery, Google Authenticator, recovery codes). Adding SMS as an option makes your account less secure, not more. Unfortunately, most sites do not allow you to turn off SMS recovery even if they offer other 2FA options. Security is only as strong as the weakest link, and SMS…

The problem lies in that Google Authenticator is tied to a device, so if you upgrade it or lose it, you’re f’d. I also doubt many use/print recovery codes, and if they do, good luck finding them 7 years later.

Overall the situation isn’t great.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#73
post #28

Earlier quoted context omitted.

Why doesn't Google get rid of SMS recovery completely? It's a huge security flaw that can be easily exploited.

It depends on your threat level. If you're just trying to avoid phishing, it's great, something like 99.9% effective. However, if you're worried you'll be targeted, where someone will go through the effort to do this to you specifically, then it's not a good choice.

2FA does not fully protect you against phishing. The attacker can just passthrough all credentials including your 2FA code. It limits the attack to a time window and any further security sensitive changes that require 2FA may be protected unless the user naively re-enters their code.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#74
post #11

Is there some mobile provider that has a way higher standard of security? Something like "Cloudflare for SIM"

Google Fi requires you to have access to your google account to port or sim swap your number. So if you have real 2FA you should be safer.

I just had my AT&T sim swapped two weeks ago. According to police, the sim swappers are insiders at the telcos or have compromised corporate credentials and are logging into the telco admin portal and processing the swaps themselves.

I’ve now switched to Google Fi. I’m banking on the assumption that Google doesn’t keep an admin portal open to the internet and that they don’t give sim swap/port access to employees that aren’t paid well enough to be willing to take a small bribe to swap the sims.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#75
post #11

Is there some mobile provider that has a way higher standard of security? Something like "Cloudflare for SIM"

I noticed that author assumed he couldn't call 611 and took how long to contact via alternate phones. I'm pretty sure 611 works without a SIM card.

no sim is no calls or sms. however, an inactive sim is allowed to call 611 (or provider equivalent) , 911(or local equivalent) and a few such emergency numbers generally. You do need the sim to be in working order and in the device. but it does not need to be activated.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#76
post #42
post #23

Earlier quoted context omitted.

> Interestingly Heathrow police didn't care as the "theft" was only a $5 SIM card and not a "high enough value item" to warrant investigation. What about the part that's "being a part of a criminal conspiracy to steal $40k?" I guess that's not something for the airport police to deal with though.

Ayup. Here's what I got back from them: In light of the extended Fraud on your account, I believe that due to the 7 day lapse between you collecting the SIM and returning to the USA, then your details could have been compromised anywhere. In all probability, this occurred in the USA as this is where the accounts have been set up and believed the fraudsters would have had to have been in order to benefit from the crim…

Anyway, thanks for sharing. This is not exactly an obvious fraud.

I think one way to prevent it, aside from remembering to not let your SIM off your hands is to mark/paint your SIM and make it unique and easily recognizable.

Then you can deal with it immediatelly, even if you forget the rule to not give your SIM temporarily to others. (You'll probaly not forget, but people who may not have your experience and still want to protect themselves against this, may.) Also the attackers will not probably attempt to swap unique looking SIM in the first place.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#77
Google Authenticator is a huge question.

While there is apparently a desktop interface, if someone gets access to my phone, they have the live access codes right there. When the SIM is stolen, can the authenticator also be accessed with the new location of that identity?

The process for moving Authenticator involves receiving a six digit Google code on your phone -- which was just effectively stolen with the SIM...

While Google may have built in protections, they are not obvious at this point to me, a casual user of Google Authenticor.

Does anyone have any more information to keep this more secure?

Re: SIM swap horror story: I've lost decades of data and Google won't help

#78

Earlier quoted context omitted.

Thanks for reminding me... again... about this. Why haven't I backed up my gmail data yet? It has been years since I realized I have to do it. Why haven't I done it?

Because it's not easy to automate.

They now have a feature that lets you schedule it to run every few months. You could probably automate the download from your email client.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#79
post #42

Earlier quoted context omitted.

Ayup. Here's what I got back from them: In light of the extended Fraud on your account, I believe that due to the 7 day lapse between you collecting the SIM and returning to the USA, then your details could have been compromised anywhere. In all probability, this occurred in the USA as this is where the accounts have been set up and believed the fraudsters would have had to have been in order to benefit from the crim…

I understand your frustration, but I also think they have a point. What you're telling us is all based on your educated guesses as to how they might have pulled this. There are things that feel a bit weird and I'm guessing you have no evidence to prove them, such as the scammer shipping the real SIM back to Atlanta in time before you realise the issue. How did you realise the SIM card you were handed was fake? Couldn…

Is SIM cloning still easily doable?

Re: SIM swap horror story: I've lost decades of data and Google won't help

#80
post #11

Is there some mobile provider that has a way higher standard of security? Something like "Cloudflare for SIM"

I noticed that author assumed he couldn't call 611 and took how long to contact via alternate phones. I'm pretty sure 611 works without a SIM card.

How would the phone know which network to 611?
Post reply on HN