Live data from Hacker News

SIM swap horror story: I've lost decades of data and Google won't help

zdnet.com

101–110 of 303 posts

Re: SIM swap horror story: I've lost decades of data and Google won't help

#101
post #76
post #42

Earlier quoted context omitted.

Ayup. Here's what I got back from them: In light of the extended Fraud on your account, I believe that due to the 7 day lapse between you collecting the SIM and returning to the USA, then your details could have been compromised anywhere. In all probability, this occurred in the USA as this is where the accounts have been set up and believed the fraudsters would have had to have been in order to benefit from the crim…

Anyway, thanks for sharing. This is not exactly an obvious fraud. I think one way to prevent it, aside from remembering to not let your SIM off your hands is to mark/paint your SIM and make it unique and easily recognizable. Then you can deal with it immediatelly, even if you forget the rule to not give your SIM temporarily to others. (You'll probaly not forget, but people who may not have your experience and still w…

Other ways are to use phones with 2 SIM card slots or simply use a local carrier with decent international roaming support or (of course) carry a paperclip to just do it yourself.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#102

Earlier quoted context omitted.

I'll agree that POP is pretty easy and worthwhile here. One caveat: I'm not certain that it's identical to what Takeout provides. I downloaded the mbox file via Takeout and the Takeout version was a fair bit larger than my Thunderbird mbox file as I recall. Maybe Thunderbird stores the emails more efficiently than Takeout? I should examine this more closely. As far as I am aware there are no missing emails in Thunder…

Attachments?

[deleted]

Re: SIM swap horror story: I've lost decades of data and Google won't help

#103
post #89
post #10

I certainly didn't appreciate how much SIM cards are the keys to our modern lives until mine got stolen. Interestingly, my thieves took a different tack: they actually stole the physical SIM card! You might ask how this could happen: I was traveling internationally and had a friendly guy at an official kiosk in the Heathrow arrivals hall swap out my SIM card for a local SIM. He palmed my SIM and gave me back a dud wi…

How did they get your 4-digit PIN? Don't you have to enter it on every reboot?

Phones' PINs aren't connected to SIMs. I have to enter my PIN on reboot, even if I removed my SIM. Putting the SIM in a phone without a PIN results in nothing being required.

Edit: Thanks for correcting me- I guess my SIM does not have a PIN.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#104
post #50

Earlier quoted context omitted.

U2F keys are great but I look forward to the day when they’re more widely available outside the US. And I’m still waiting for my replacement from Feitian for the recent vulnerability. Not to say you shouldn’t use them, but... they have their limits. Particularly Advanced Protection which forces you to use Google’s browser in many situations and disables API access so I can’t use the API to get my own data, only Googl…

Yeah, Chromium is needed to add keys, which effectively means you can’t enable Advanced Protection without Chromium. I personally ran into this wall. I acknowledge that this sucks, as a person that intentionally only uses Firefox, but to be clear logging in and most other operations work absolutely fine with Advanced Protection. Does it really disable all API access? I thought it only blocked certain OAuth scopes, bu…

Seems like Firefox U2F is just disabled by default: https://www.yubico.com/2017/11/how-to-navigate-fido-u2f-in-f... (tl;dr: Open about:config, search for u2f, enable)

With that done, GitHub prompts me for my key. My Linux office workstation is missing the necessary udev rule, so I couldn't test more. (Funnily, pressing Cancel caused them to send me a SMS, so their 2FA is practically worthless).

Re: SIM swap horror story: I've lost decades of data and Google won't help

#105
Don't use an sms/voice phone number as part of your 2-step verification in Google.

In the past, I did use a verizon landline phone number as Verizon had the ability to "lock/freeze" that number from any outside changes, but I got rid of my landline a while ago.

Also, print out some backup codes and stick it in your wallet.

I have no idea what month and year I created my google account, and google doesn't seem to make that info available to you in a simple manner.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#106
This is a good reminder to never entrust Google with sensitive financial records and documents. Sure, the cloud service is a convenience, but, if a hacker accesses your account, it doesn't take much to download copies of those documents and use them against you.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#107

Google really fails hard in the face of providing support when issues like this occur. The average person has to try various automated account recovery options which, as in the author's case, are readily changeable the moment the account is compromised, rendering them somewhat useless, and then users are out of luck. It's a situation that is mind-boggling. Users as asked to place a significant chunk of their digital…

> People who pay for G-suite have real support, even ::gasp:: telephone support. Why on earth does google not offer this to consumer users?

I know people are getting sick of this phrase, but I'm going to repeat it here anyway because it answers your question perfectly: why doesn't Google have customer support? They do, but if the product is free, you're not the customer.

As you note, Google does have real customer support for people who pay. The other people are not customers, they are advertising targets. Why waste money on support for them?

Re: SIM swap horror story: I've lost decades of data and Google won't help

#108
Don't use 2FA, if the 2nd factor is anything mobile-based. Use strong passphrases, and type them when you need access to the assets they protect.

There is the concept of "security VS convenience", a trade-off you make when using secured assets. 2FA is convenience just as much as it is security. By having SMS as a method to reset a password, you reduce the attackers workload from cracking a difficult password to "compromise your mobile phone physically or electronically". I trust my passphrases much more than my mobile device and/or carrier.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#109

A few suggestions: 1) Call your cellphone carrier and ask to set up a password/PIN to be used for when you call into the customer service phone number. 2) Consider your phone number and SIM card insecure. The phone carriers are ignoring the SIM swap problem even though they know how much damage it's causing. Give your phone number to as few companies as possible. Phone services such as Google Voice work without a SIM…

> Call your cellphone carrier and ask to set up a password/PIN Note that, at least for TMobile, AT&T, and Verizon, the password/PIN is presented to the CSR in plaintext (as they verify the pin over the phone verbally). I'd assumed they'd transfer to some pin-capture applet to verify, but nope. > Use an authentication app, such as Google Authenticator If you decide on Google Authenticator, make sure you scan the barco…

Authy allows you to recover your account using... SMS. So this is also vulnerable to SIM swapping. https://medium.com/mycrypto/what-to-do-when-sim-swapping-hap...

Re: SIM swap horror story: I've lost decades of data and Google won't help

#110
post #22

Earlier quoted context omitted.

You can use it in any browser. You have to register it in chrome. Crappy, but not a line in the sand I'm willing to die on.

Conventionally, one metaphorically chooses a _hill_ to die on, and lines in the sand are only crossed or redrawn, not died on. The insistence on using Chrome is arbitrary and I don't like it. The use of U2F rather than WebAuthn at least has a technical justification (older Android devices can't do WebAuthn, and while it's backward compatible in the sense that you can use a WebAuthn authentication having signed up wit…

> The insistence on using Chrome is arbitrary and I don't like it.

Supposedly this limitation is because Firefox doesn't implement the JavaScript calls that permit a U2F-calling site to know the type of U2F key being used and Google wants to enforce, when enrolling for ATP, that at least one of the two keys being enrolled can be used wirelessly (Bluetooth or NFC).

I don't agree with it either but will only truly be mad if/when Mozilla implements the requisite call and Google still blocks enrollment without Chrome.

Post reply on HN