Live data from Hacker News

SIM swap horror story: I've lost decades of data and Google won't help

zdnet.com

171–180 of 303 posts

Re: SIM swap horror story: I've lost decades of data and Google won't help

#171
>If anyone has tips on how I might get my Google and Twitter accounts back, I would greatly appreciate the feedback.

I know of one approach that might get results, but he's already done it: publicly shame them in an article. It's the only way to get results from these algorithm-driven companies that lack anything resembling an actual customer service department.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#172

Google really fails hard in the face of providing support when issues like this occur. The average person has to try various automated account recovery options which, as in the author's case, are readily changeable the moment the account is compromised, rendering them somewhat useless, and then users are out of luck. It's a situation that is mind-boggling. Users as asked to place a significant chunk of their digital…

It’s $20/year to get 100GB of space for GoogleOne. Worth it so that you have a paid account with support options.

The author mentions that they are a paying customer.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#173
post #28
post #12

Anyone who wants to defend themselves, consider using U2F where you can and Google Advanced Protection. I just recently picked up a bluetooth security key because one is needed to log an iPhone into an account using advanced protection; there is no SMS backup loophole. The Titan key bundle comes with a bluetooth and USB key, which is enough to get started, though frankly you probably want a couple additional backup k…

Why doesn't Google get rid of SMS recovery completely? It's a huge security flaw that can be easily exploited.

When you first enable 2FA with Google you have to do SMS (at least that was the requirement last time I did it). However, once you've defined an alternative 2FA method (Google auth, u2f key, etc) then you can remove the SMS method completely.

Believe it or not banks are really bad at security. They are so bad at it that they don't even realize how bad at it they are. But the banks all copy from each other so "what the other guy is doing" is more or less their justification for what they do. Most of them have little to no idea why they do what they do for IT security, they just do what the Computer Security for Dummies book says to do (walk through the IT security department at any big bank and I bet you there is a dog eared copy of that tome on every desk)

Synchrony is one of the worst offenders, they won't even let you change your password without doing SMS verification, and their source of phone numbers is a Transunion skip trace database (which you can't change or remove any information from), so getting past Synchrony can be as easy as filling out a contest form at a mall, waiting for the phone number to appear with Transunion, then choosing that phone number to do SMS verification. It might take a couple months but payoff can be huge.

My hero at the moment is Capital One, they allow you to do e-mail authentication instead of SMS, and their iOS app also doubles as an additional factor (one requiring you to enter your password or use touch ID to use).

I was also extremely happy to find that the brokerage Robinhood offers Google Auth as a second factor. E*Trade also offers 2FA but a proprietary token w/ lcd display (which they happily charge you for).

My trick has been to give banks a false phone number that rings busy forever. That does effectively keep me from using banks that require SMS authentication, but there are more then enough that either offer other methods or drop their SMS requirement if you list your mobile number as your home number (indicating that its a wired phone and can't receive SMS). That doesn't keep my Synchrony accounts secure but there are enough protections around credit cards that my liability would be $50 at worst, with Synchrony having to eat the remainder of the loss.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#174
The lack of customer support provided my tech companies today is pathetic. Combine this with Google's decreasing effectiveness in looking up solutions to technical problems and we get this :(

I have a really odd, obscure problem with SMB and Windows 10 and would really like to just call up a Microsoft tech support hotline like they used to have, except they don't even offer a paid service for that any more to consumers. Got a problem with Windows? Get fucked!

Re: SIM swap horror story: I've lost decades of data and Google won't help

#175
post #28
post #12

Anyone who wants to defend themselves, consider using U2F where you can and Google Advanced Protection. I just recently picked up a bluetooth security key because one is needed to log an iPhone into an account using advanced protection; there is no SMS backup loophole. The Titan key bundle comes with a bluetooth and USB key, which is enough to get started, though frankly you probably want a couple additional backup k…

Why doesn't Google get rid of SMS recovery completely? It's a huge security flaw that can be easily exploited.

Because, depending on your risk profile, it can be very helpful:

> We found that an SMS code sent to a recovery phone number helped block 100% of automated bots, 96% of bulk phishing attacks, and 76% of targeted attacks.

* https://security.googleblog.com/2019/05/new-research-how-eff...

Not everyone has to worry about being targeted by nation states.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#177

Earlier quoted context omitted.

I noticed that author assumed he couldn't call 611 and took how long to contact via alternate phones. I'm pretty sure 611 works without a SIM card.

How would the phone know which network to 611?

I would expect it to work for a carrier-branded device even with no SIM card, unless the device has been flashed with a stock firmware from the OEM.

For a non-carrier-branded device though, perhaps the presence of a SIM card is required.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#178
post #49

Unlike what the OP stated, the key is NOT to list you phone number as an SMS 2FA recovery option. Only use the non-SMS options (e.g. app-based recovery, Google Authenticator, recovery codes). Adding SMS as an option makes your account less secure, not more. Unfortunately, most sites do not allow you to turn off SMS recovery even if they offer other 2FA options. Security is only as strong as the weakest link, and SMS…

The problem lies in that Google Authenticator is tied to a device, so if you upgrade it or lose it, you’re f’d. I also doubt many use/print recovery codes, and if they do, good luck finding them 7 years later. Overall the situation isn’t great.

I still have my Google Account recovery codes in my wallet that I first generated in 2011.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#179

Don't use 2FA, if the 2nd factor is anything mobile-based. Use strong passphrases, and type them when you need access to the assets they protect. There is the concept of "security VS convenience", a trade-off you make when using secured assets. 2FA is convenience just as much as it is security. By having SMS as a method to reset a password, you reduce the attackers workload from cracking a difficult password to "comp…

This doesn't make sense. Why not use both 2fa AND a strong passphrase? To get to the second factor the attacker still needs your password. There is nothing that says you should use a simple password if you have 2fa configured.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#180

Google really fails hard in the face of providing support when issues like this occur. The average person has to try various automated account recovery options which, as in the author's case, are readily changeable the moment the account is compromised, rendering them somewhat useless, and then users are out of luck. It's a situation that is mind-boggling. Users as asked to place a significant chunk of their digital…

This is why I panicked when they announced they won't sync Google Photos with Google Drive anymore. With the sync, I can setup one of my computers to constantly download the photos and then copy it onto a local backup and an online backup. If my Google Account gets locked - I'll just copy the photos into something else and move on with my life. They removed that saying it's confusing to users - all the while it was a…

How is your solution different from uploading to Google Drive?
Post reply on HN