Live data from Hacker News

SIM swap horror story: I've lost decades of data and Google won't help

zdnet.com

181–190 of 303 posts

Re: SIM swap horror story: I've lost decades of data and Google won't help

#181
post #30
post #8

The industry needs to learn that sms 2fa is not secure because getting a sim for someone else is so easy. And this happening in every country.

I would say that for the average user sms 2FA is secure enough. P.S. I might have a different perspective as where i am from, there really aren't important services (banks etc.) that are using sms 2FA. Mobile operators doesn't ship SIM cards over mail, you can get a new SIM only in person providing ID (or PIN/PUK in case of prepaid cards). Probably my country is just too small market for these kind of attacks so i fe…

You're saying that you're safe because you're not an interesting target. People tend to agree that security through obscurity is not a good strategy.

As for how hackers can swap someone's SIM, consider:

- Does the 20 year old minimum wage employee working at that store know how to spot a good quality fake ID card?

- What about hackers bribing an employee?

Re: SIM swap horror story: I've lost decades of data and Google won't help

#182
I will never understand how someone can have all his digital life in one single place.. I mean, mail eMail, Passwords to all other sites, scanned documents - all in google? That is asking for trouble. Also, 2FA via Text makes your account unsafer, if any.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#183

> It turns out that the 2FA with text messaging sent to a cell phone may be useless when hackers steal your SIM right out from under you. The most annoying part about this is that Twitter demands your phone number. You can't use another method for 2FA, such as U2F or OTP. I assume it's not at all because they want to authorize you or keep your account safe, but rather because they want to be able to identify you. Use…

> You can't use another method [with Twitter] for 2FA, such as U2F or OTP.

Are you sure?

* https://www.yubico.com/works-with-yubikey/catalog/twitter/

Re: SIM swap horror story: I've lost decades of data and Google won't help

#184
> This included tax returns, account passwords for my wife in case I died, personal documents and spreadsheets, and just about everything I had paper copies of at home.

This is why you should never store passwords on your computer / cloud in plain text.

> Given that I had 2FA enabled for my bank account and the bank account info on Google Drive, it was just a matter of time before the thief started stealing my money.

Is it common in the United States to allow online banking without any physical second factor? My bank requires me to use some kind of device similar to https://en.wikipedia.org/wiki/Chip_Authentication_Program with my card and code to login or execute transactions. I think most other banks in my country require something similar.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#185
post #4

This is a good place to remind everyone of Google Takeout [1]. Back up all of your data. Don't let this horror story happen to you. [1] https://takeout.google.com/settings/takeout

I was just about to set this up to automatically put everything in my organization's Box every six months, but: > With access to your XXX@YYY.ZZZ Box account, Google Download Your Data can: > Read and write all files and folders stored in Box Nope. Download link it is.

Yeh that's unfortuante but it is normal for box's API. This isn't Google being overly grabby, its the only scope available to third party read and writing to box.

The API scope doesn't have any knowledge of individual files or applications. https://developer.box.com/docs/scopes

Conversely, Google Drive does have scopes available for Application specific folder read/write https://developers.google.com/drive/api/v3/appdata

So box needs to up its game.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#186

Earlier quoted context omitted.

This is why I panicked when they announced they won't sync Google Photos with Google Drive anymore. With the sync, I can setup one of my computers to constantly download the photos and then copy it onto a local backup and an online backup. If my Google Account gets locked - I'll just copy the photos into something else and move on with my life. They removed that saying it's confusing to users - all the while it was a…

How is your solution different from uploading to Google Drive?

Editing, search, organization, sharing and viewing tools. Google Photos is a fantastic UI for that - provided, the pictures actually live in my Drive.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#187
In the space of the afternoon after reading this article, I removed SMS 2FA from all my accounts, installed Authy, added all my accounts to it, found out Authy is also insecure[0], reconfigured it to be less insecure, and basically despaired.

My solution going forward will be to spend all of my money each month so there's nothing to steal, and have a terrible reputation online that therefore can't be ruined.

[0] https://medium.com/p/1367f296ef4d#681f

Re: SIM swap horror story: I've lost decades of data and Google won't help

#188

> It turns out that the 2FA with text messaging sent to a cell phone may be useless when hackers steal your SIM right out from under you. The most annoying part about this is that Twitter demands your phone number. You can't use another method for 2FA, such as U2F or OTP. I assume it's not at all because they want to authorize you or keep your account safe, but rather because they want to be able to identify you. Use…

> You can't use another method [with Twitter] for 2FA, such as U2F or OTP. Are you sure? * https://www.yubico.com/works-with-yubikey/catalog/twitter/

They still ban your account without valid non-VOIP phone.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#189

Recently I discovered that Facebook has a policy that no one with pending misdemeanors can be hired if they are just a contractor. We recently had to turn away a 23 year old combat veteran who had deployed to Afghanistan because he had a pending Class C misdemeanor. That’s a max fine of $50 for the state this was in. All for a $16.50 an hour job. The amount of indifference to suffering by people in the corporate worl…

Are you sure you are commenting in the right thread?

The article did mention that their Facebook account was the only one that wasn't compromised.

> Through all of these hacks, it was interesting to find that Facebook was the one reliable and secure service under my control.

Perhaps their comment was attempting to provide some anecdotal data in an effort to explain why the author's Facebook account remained secure.

Though I agree with you in the sense that it's far more likely that they simply commented on the wrong article. :)

Re: SIM swap horror story: I've lost decades of data and Google won't help

#190

A few suggestions: 1) Call your cellphone carrier and ask to set up a password/PIN to be used for when you call into the customer service phone number. 2) Consider your phone number and SIM card insecure. The phone carriers are ignoring the SIM swap problem even though they know how much damage it's causing. Give your phone number to as few companies as possible. Phone services such as Google Voice work without a SIM…

> 2) Consider your phone number and SIM card insecure.

Your phone number is an obvious attack vector. I think having a dual sim phone with 2fa dedicated number that is not publicly associated with you, possibly with the carrier that has it's security in order, would decrease the odds of getting hacked.

Post reply on HN