Earlier quoted context omitted.
The SIM ICCID that I physically had in my hands upon return was different than the ICCID that ATT had on file for me. I also watched the dude do it right in front of me, but of course SIM cards are quite easy to palm. It was the "Tourist Services" kiosk and I bought a £20 Lebara card. He very kindly taped the ATT card down to the Lebara cardboard packaging, and I wasn't able to remove that tape without damaging it so…
Just playing devil's advocate, the ICCID on file would also be different if they had managed to compromise your account and change the sim associated with it.
SIM swap horror story: I've lost decades of data and Google won't help
211–220 of 303 posts
Re: SIM swap horror story: I've lost decades of data and Google won't help
#212This is why I would like to trust my digital identity to my bank. They have enough local, physical presence so that I could show up in person and prove who I am. Also the personnel is already familiar with checking the identity and hopefully less suspectiple to social engineering. 2FA tokens and codesheets without SMS backup are secure, but bit tricky to manage. Takes some effort to distribute to different, secure pl…
Re: SIM swap horror story: I've lost decades of data and Google won't help
#213Earlier quoted context omitted.
That's less common wisdom and more of a catchy but dumb meme. There are all sorts of things you can buy that have crappy-to-nonexistent customer service.
Sure, but even Comcast isn't as bad as Google; not as much depends on Comcast, and Google has mountains of p[eople's key life-altering data, yet it is nearly impossible to speak with a human that has any capability to effect a change. As with every generalizations, there are exceptions, but they generally only prove the rule.
Customer service has more to do with company-specific culture than what you actually paid. There are good and bad examples in every industry (or even with the same company).
Re: SIM swap horror story: I've lost decades of data and Google won't help
#214Earlier quoted context omitted.
You can use it in any browser. You have to register it in chrome. Crappy, but not a line in the sand I'm willing to die on.
Conventionally, one metaphorically chooses a _hill_ to die on, and lines in the sand are only crossed or redrawn, not died on. The insistence on using Chrome is arbitrary and I don't like it. The use of U2F rather than WebAuthn at least has a technical justification (older Android devices can't do WebAuthn, and while it's backward compatible in the sense that you can use a WebAuthn authentication having signed up wit…
Re: SIM swap horror story: I've lost decades of data and Google won't help
#215Don't use 2FA, if the 2nd factor is anything mobile-based. Use strong passphrases, and type them when you need access to the assets they protect. There is the concept of "security VS convenience", a trade-off you make when using secured assets. 2FA is convenience just as much as it is security. By having SMS as a method to reset a password, you reduce the attackers workload from cracking a difficult password to "comp…
This doesn't make sense. Why not use both 2fa AND a strong passphrase? To get to the second factor the attacker still needs your password. There is nothing that says you should use a simple password if you have 2fa configured.
Re: SIM swap horror story: I've lost decades of data and Google won't help
#216> This included tax returns, account passwords for my wife in case I died, personal documents and spreadsheets, and just about everything I had paper copies of at home. This is why you should never store passwords on your computer / cloud in plain text. > Given that I had 2FA enabled for my bank account and the bank account info on Google Drive, it was just a matter of time before the thief started stealing my money.…
Re: SIM swap horror story: I've lost decades of data and Google won't help
#217Anyone who wants to defend themselves, consider using U2F where you can and Google Advanced Protection. I just recently picked up a bluetooth security key because one is needed to log an iPhone into an account using advanced protection; there is no SMS backup loophole. The Titan key bundle comes with a bluetooth and USB key, which is enough to get started, though frankly you probably want a couple additional backup k…
What is your contingency plan for when that physical key is lost, stolen or damaged?
Re: SIM swap horror story: I've lost decades of data and Google won't help
#218Earlier quoted context omitted.
Google One advertises real support for consumer users... but it turns out they can't really so anything but read support docs to you.
Is this a reference to something? I haven't heard much about Google One's support good or bad. The concern I'd have with G-One is that if you lost access to your account, you also aren't a Google One customer, and the support likely won't assist you. Creating a chicken/egg situation.
Re: SIM swap horror story: I've lost decades of data and Google won't help
#219Earlier quoted context omitted.
Make it something you can pay in advance, then. For a fee, you get marked as a high-risk/high-value account, get the recovery service and risky factors of authentication get extra scrutiny, etc.
You can get extra security from Google for free. https://landing.google.com/advancedprotection/
https://mobile.twitter.com/patio11/status/114040469625693798...
Re: SIM swap horror story: I've lost decades of data and Google won't help
#220This might seem impractical for people who live somewhere that the provider doesn't have an office, but it actually isn't. There is a nationwide, readily available mechanism already in place for this. They are called notary publics.
It could work like this:
1. You request account recovery, and pay the fee, and provide your physical contact information.
2. The provider hires a notary public in your area, and sends them a form for you to sign authorizing the account recovery.
3. The notary meets with you, verifies your identity, notarizes your signature on the form, and then lets your provider know that this has successfully completed.
4. Now that the provider knows the request was legitimate, the recovery or transfer can go through.