Live data from Hacker News

SIM swap horror story: I've lost decades of data and Google won't help

zdnet.com

131–140 of 303 posts

Re: SIM swap horror story: I've lost decades of data and Google won't help

#132
By all means use hosted email, but if you want to stop this happening to you make sure you register your own domain! At least then you can open a new mail account and move the domain to this. That way you can make sure you can recover your other accounts...as long as you don't lose you DNS of course!

Re: SIM swap horror story: I've lost decades of data and Google won't help

#133
post #77

Google Authenticator is a huge question. While there is apparently a desktop interface, if someone gets access to my phone, they have the live access codes right there. When the SIM is stolen, can the authenticator also be accessed with the new location of that identity? The process for moving Authenticator involves receiving a six digit Google code on your phone -- which was just effectively stolen with the SIM... W…

Last time I switched phones I had to set up GA from scratch, re-scanning the seeds on every account. The initial SMS code was just to attach an authenticator to a new device. Someone compromising your phone number shouldn't be able to get access to your codes, they would need the physical device.

Also note that there is no official desktop client, anything that claims to be is 3rd party and wouldn't be connected to your current codes.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#134
post #89
post #10

I certainly didn't appreciate how much SIM cards are the keys to our modern lives until mine got stolen. Interestingly, my thieves took a different tack: they actually stole the physical SIM card! You might ask how this could happen: I was traveling internationally and had a friendly guy at an official kiosk in the Heathrow arrivals hall swap out my SIM card for a local SIM. He palmed my SIM and gave me back a dud wi…

How did they get your 4-digit PIN? Don't you have to enter it on every reboot?

SIM PINs aren't enabled by default on iPhones and are independent of your device lock code.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#135
post #49

Unlike what the OP stated, the key is NOT to list you phone number as an SMS 2FA recovery option. Only use the non-SMS options (e.g. app-based recovery, Google Authenticator, recovery codes). Adding SMS as an option makes your account less secure, not more. Unfortunately, most sites do not allow you to turn off SMS recovery even if they offer other 2FA options. Security is only as strong as the weakest link, and SMS…

The problem lies in that Google Authenticator is tied to a device, so if you upgrade it or lose it, you’re f’d. I also doubt many use/print recovery codes, and if they do, good luck finding them 7 years later. Overall the situation isn’t great.

[deleted]

Re: SIM swap horror story: I've lost decades of data and Google won't help

#136
post #77

Google Authenticator is a huge question. While there is apparently a desktop interface, if someone gets access to my phone, they have the live access codes right there. When the SIM is stolen, can the authenticator also be accessed with the new location of that identity? The process for moving Authenticator involves receiving a six digit Google code on your phone -- which was just effectively stolen with the SIM... W…

You can generate backup codes and print/store them securely[0]. That is independent of your phone.

[0]: https://myaccount.google.com/signinoptions/two-step-verifica...

Re: SIM swap horror story: I've lost decades of data and Google won't help

#137

Earlier quoted context omitted.

fun fact about sims. they run a java operating system which can be accessed via binary SMS messages (apdu messages) - invisible to your phone, with the right sim pin, they can get filesystem access in this 'os' and steal your private keys and phone identification numbers, effectively allowing them to mitm / clone your phone and calls/sms etc. that being said it's just plain silly how important these crummy devices ar…

Is this true in say an iPhone? I don’t think there’s even a way to set a sim pin?

You can setup a SIM PIN, but I hadn't enabled it and I bet few folks do as it's not connected to the device lock code and not on by default: https://support.apple.com/en-us/HT201529

Re: SIM swap horror story: I've lost decades of data and Google won't help

#138
post #12

Anyone who wants to defend themselves, consider using U2F where you can and Google Advanced Protection. I just recently picked up a bluetooth security key because one is needed to log an iPhone into an account using advanced protection; there is no SMS backup loophole. The Titan key bundle comes with a bluetooth and USB key, which is enough to get started, though frankly you probably want a couple additional backup k…

This unfortunately is useless. Account recovery will still allow the hacker to use the phone number that has just been swaped to logon to the email. The weakest link is what matters and in this case you are just putting a bigger door lock on the front door while leaving your back door open.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#139
Google Takeout is your friend. I download all my drive, calendar, email, etc once a month. (Not photos, since I have those already.)

It pays to be skeptical with your data. 3 copies. 2 local one offsite. If your only copy is offsite in the control of someone else... that's a terrible decision.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#140
post #49

Unlike what the OP stated, the key is NOT to list you phone number as an SMS 2FA recovery option. Only use the non-SMS options (e.g. app-based recovery, Google Authenticator, recovery codes). Adding SMS as an option makes your account less secure, not more. Unfortunately, most sites do not allow you to turn off SMS recovery even if they offer other 2FA options. Security is only as strong as the weakest link, and SMS…

The problem lies in that Google Authenticator is tied to a device, so if you upgrade it or lose it, you’re f’d. I also doubt many use/print recovery codes, and if they do, good luck finding them 7 years later. Overall the situation isn’t great.

I just went through this situation with a couple non-Google companies when I upgraded my phone, not realizing that their authentication info wouldn't transfer when Google transferred my data to the new phone. I thought I had double-checked that I had everything, but this got missed.

It was a pain for all of them, but it was worst for the ones that I had no other auth systems set up. (Or the ones that had my old phone number for SMS still, even though I thought I'd changed it everywhere.)

In the end, there's still no good system for real security. You're either stuck with a device you might lose (or someone might steal), or stuck with an account that you might cancel (or someone might steal). Or use biometrics which are just not ready for prime time.

Post reply on HN