Live data from Hacker News

SIM swap horror story: I've lost decades of data and Google won't help

zdnet.com

91–100 of 303 posts

Re: SIM swap horror story: I've lost decades of data and Google won't help

#91
post #59
post #8

The industry needs to learn that sms 2fa is not secure because getting a sim for someone else is so easy. And this happening in every country.

SMS 2FA is fine. 2FA adds another layer on top of your password. The second factor doesn’t have to be particularly secure to make you safer. The problem is SMS account recovery , which is a really bad idea.

> The problem is SMS account recovery, which is a really bad idea.

The problem is that a lot of services tie the two together. Often one implies the other. Even if it doesn't, though, it's also easier to social engineer -- "look! I have access to the 2fa phone number! I just can't access my password manager!"

Re: SIM swap horror story: I've lost decades of data and Google won't help

#92
post #21

Earlier quoted context omitted.

Because it's not easy to automate.

Gmail alone is easy - use POP in a mail client, set it to mark stuff read, leave it on the server etc https://support.google.com/mail/answer/7104828?hl=en

I'll agree that POP is pretty easy and worthwhile here.

One caveat: I'm not certain that it's identical to what Takeout provides. I downloaded the mbox file via Takeout and the Takeout version was a fair bit larger than my Thunderbird mbox file as I recall. Maybe Thunderbird stores the emails more efficiently than Takeout? I should examine this more closely. As far as I am aware there are no missing emails in Thunderbird, though I could write a script to be certain.

Edit: Seems that I misremembered. The Takeout file seems to be appreciably smaller than what Thunderbird has, but in line with what Gmail reports at the bottom. I guess Thunderbird is actually less efficient than Gmail. Attachments might explain some of this, as I deleted some attachments in Gmail that I kept in Thunderbird.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#93
post #49

Unlike what the OP stated, the key is NOT to list you phone number as an SMS 2FA recovery option. Only use the non-SMS options (e.g. app-based recovery, Google Authenticator, recovery codes). Adding SMS as an option makes your account less secure, not more. Unfortunately, most sites do not allow you to turn off SMS recovery even if they offer other 2FA options. Security is only as strong as the weakest link, and SMS…

The problem lies in that Google Authenticator is tied to a device, so if you upgrade it or lose it, you’re f’d. I also doubt many use/print recovery codes, and if they do, good luck finding them 7 years later. Overall the situation isn’t great.

I would recommend saving the recovery codes in a password manager app (that is not your browser)

Re: SIM swap horror story: I've lost decades of data and Google won't help

#94
post #50

Earlier quoted context omitted.

U2F keys are great but I look forward to the day when they’re more widely available outside the US. And I’m still waiting for my replacement from Feitian for the recent vulnerability. Not to say you shouldn’t use them, but... they have their limits. Particularly Advanced Protection which forces you to use Google’s browser in many situations and disables API access so I can’t use the API to get my own data, only Googl…

Yeah, Chromium is needed to add keys, which effectively means you can’t enable Advanced Protection without Chromium. I personally ran into this wall. I acknowledge that this sucks, as a person that intentionally only uses Firefox, but to be clear logging in and most other operations work absolutely fine with Advanced Protection. Does it really disable all API access? I thought it only blocked certain OAuth scopes, bu…

Youtube/YoutubeTV seem to be walled off on 2nd factor auth. I've been able to log into both on browsers w/o 2nd factor and then get prompted when logging into web gmail.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#95
post #49

Unlike what the OP stated, the key is NOT to list you phone number as an SMS 2FA recovery option. Only use the non-SMS options (e.g. app-based recovery, Google Authenticator, recovery codes). Adding SMS as an option makes your account less secure, not more. Unfortunately, most sites do not allow you to turn off SMS recovery even if they offer other 2FA options. Security is only as strong as the weakest link, and SMS…

The problem lies in that Google Authenticator is tied to a device, so if you upgrade it or lose it, you’re f’d. I also doubt many use/print recovery codes, and if they do, good luck finding them 7 years later. Overall the situation isn’t great.

> The problem lies in that Google Authenticator is tied to a device, so if you upgrade it or lose it, you’re f’d.

You can save the QR code that was used during setup to repeat the onboarding at any time. You can also use Authy, 1Password, or another service that lets you store the one-time password somewhere else. Or use U2F devices when possible.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#96

This is why I would like to trust my digital identity to my bank. They have enough local, physical presence so that I could show up in person and prove who I am. Also the personnel is already familiar with checking the identity and hopefully less suspectiple to social engineering. 2FA tokens and codesheets without SMS backup are secure, but bit tricky to manage. Takes some effort to distribute to different, secure pl…

My good bank has no physical presence whatsoever. I mean, I presume they operate a call centre somewhere, maybe in Scotland, but I've never seen it.

They can reach out and cause things to happen at a distance, but I don't want that used to authenticate me. They used it when I had lost my cards, to cause me to receive a bundle of cash so I could get on with my day just paying cash everywhere.

I have a specialized OTP device with a chiclet keyboard, and a password used for normal stuff. When I do something serious, like the time I bought somewhere to live, I call them to set up the transaction, then a different random person gets assigned to call me back and verify the details - this way if one employee goes rogue they can't empty my account by claiming I called them. They have a password for me, and the second employee uses that password so that I know it's really the bank calling me.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#97
post #21

Earlier quoted context omitted.

Gmail alone is easy - use POP in a mail client, set it to mark stuff read, leave it on the server etc https://support.google.com/mail/answer/7104828?hl=en

I'll agree that POP is pretty easy and worthwhile here. One caveat: I'm not certain that it's identical to what Takeout provides. I downloaded the mbox file via Takeout and the Takeout version was a fair bit larger than my Thunderbird mbox file as I recall. Maybe Thunderbird stores the emails more efficiently than Takeout? I should examine this more closely. As far as I am aware there are no missing emails in Thunder…

Attachments?

Re: SIM swap horror story: I've lost decades of data and Google won't help

#98
post #42

Earlier quoted context omitted.

Ayup. Here's what I got back from them: In light of the extended Fraud on your account, I believe that due to the 7 day lapse between you collecting the SIM and returning to the USA, then your details could have been compromised anywhere. In all probability, this occurred in the USA as this is where the accounts have been set up and believed the fraudsters would have had to have been in order to benefit from the crim…

I understand your frustration, but I also think they have a point. What you're telling us is all based on your educated guesses as to how they might have pulled this. There are things that feel a bit weird and I'm guessing you have no evidence to prove them, such as the scammer shipping the real SIM back to Atlanta in time before you realise the issue. How did you realise the SIM card you were handed was fake? Couldn…

The SIM ICCID that I physically had in my hands upon return was different than the ICCID that ATT had on file for me. I also watched the dude do it right in front of me, but of course SIM cards are quite easy to palm. It was the "Tourist Services" kiosk and I bought a £20 Lebara card. He very kindly taped the ATT card down to the Lebara cardboard packaging, and I wasn't able to remove that tape without damaging it so I'm quite certain that it wasn't swapped elsewhere.

I did also report it to both my local police and the FTC and the FBI but never could gain traction as nobody thought it was their jurisdiction. I eventually gave up once my credit was repaired.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#99
post #4

This is a good place to remind everyone of Google Takeout [1]. Back up all of your data. Don't let this horror story happen to you. [1] https://takeout.google.com/settings/takeout

I was just about to set this up to automatically put everything in my organization's Box every six months, but:

> With access to your XXX@YYY.ZZZ Box account, Google Download Your Data can:

> Read and write all files and folders stored in Box

Nope. Download link it is.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#100
post #2

Silicon Valley has a systemic customer service problem. The price you pay for "Free" services.

His cell provider was the problem, and that is a paid service. They never should have given someone else a SIM, they are absolutely liable.
Post reply on HN