Live data from Hacker News

SIM swap horror story: I've lost decades of data and Google won't help

zdnet.com

211–220 of 303 posts

Re: SIM swap horror story: I've lost decades of data and Google won't help

#211
post #98

Earlier quoted context omitted.

The SIM ICCID that I physically had in my hands upon return was different than the ICCID that ATT had on file for me. I also watched the dude do it right in front of me, but of course SIM cards are quite easy to palm. It was the "Tourist Services" kiosk and I bought a £20 Lebara card. He very kindly taped the ATT card down to the Lebara cardboard packaging, and I wasn't able to remove that tape without damaging it so…

Just playing devil's advocate, the ICCID on file would also be different if they had managed to compromise your account and change the sim associated with it.

They also had the last-changed date (which was from when I set up my account).

Re: SIM swap horror story: I've lost decades of data and Google won't help

#212

This is why I would like to trust my digital identity to my bank. They have enough local, physical presence so that I could show up in person and prove who I am. Also the personnel is already familiar with checking the identity and hopefully less suspectiple to social engineering. 2FA tokens and codesheets without SMS backup are secure, but bit tricky to manage. Takes some effort to distribute to different, secure pl…

[deleted]

Re: SIM swap horror story: I've lost decades of data and Google won't help

#213
post #64

Earlier quoted context omitted.

That's less common wisdom and more of a catchy but dumb meme. There are all sorts of things you can buy that have crappy-to-nonexistent customer service.

Sure, but even Comcast isn't as bad as Google; not as much depends on Comcast, and Google has mountains of p[eople's key life-altering data, yet it is nearly impossible to speak with a human that has any capability to effect a change. As with every generalizations, there are exceptions, but they generally only prove the rule.

I was thinking more along the lines of manufacturer's warranties, which are often hard to actually use. Or Teslas being in the shop for weeks due to an unavailable part.

Customer service has more to do with company-specific culture than what you actually paid. There are good and bad examples in every industry (or even with the same company).

Re: SIM swap horror story: I've lost decades of data and Google won't help

#214
post #22

Earlier quoted context omitted.

You can use it in any browser. You have to register it in chrome. Crappy, but not a line in the sand I'm willing to die on.

Conventionally, one metaphorically chooses a _hill_ to die on, and lines in the sand are only crossed or redrawn, not died on. The insistence on using Chrome is arbitrary and I don't like it. The use of U2F rather than WebAuthn at least has a technical justification (older Android devices can't do WebAuthn, and while it's backward compatible in the sense that you can use a WebAuthn authentication having signed up wit…

You'd think Ubuntu chromium-browser might be acceptable for Google U2F setup -- but no, not when I tried a couple of months ago.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#215

Don't use 2FA, if the 2nd factor is anything mobile-based. Use strong passphrases, and type them when you need access to the assets they protect. There is the concept of "security VS convenience", a trade-off you make when using secured assets. 2FA is convenience just as much as it is security. By having SMS as a method to reset a password, you reduce the attackers workload from cracking a difficult password to "comp…

This doesn't make sense. Why not use both 2fa AND a strong passphrase? To get to the second factor the attacker still needs your password. There is nothing that says you should use a simple password if you have 2fa configured.

Because they can do "forgot password" using the 2fa.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#216
post #184

> This included tax returns, account passwords for my wife in case I died, personal documents and spreadsheets, and just about everything I had paper copies of at home. This is why you should never store passwords on your computer / cloud in plain text. > Given that I had 2FA enabled for my bank account and the bank account info on Google Drive, it was just a matter of time before the thief started stealing my money.…

my UK bank ties their app to my phone using an off band code i receive from a person after calling their contact number. if i reinstall my OS i need to call them to receive another code.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#217
post #12

Anyone who wants to defend themselves, consider using U2F where you can and Google Advanced Protection. I just recently picked up a bluetooth security key because one is needed to log an iPhone into an account using advanced protection; there is no SMS backup loophole. The Titan key bundle comes with a bluetooth and USB key, which is enough to get started, though frankly you probably want a couple additional backup k…

What is your contingency plan for when that physical key is lost, stolen or damaged?

You should have emergency backup keys as well printed on real paper. I have a set stored with our important files, and another in my nightstand. Having my phone stolen would be a damnable inconvenience, since that is my second factor -- although not via SIM, but via Google's in-app authentication. But it wouldn't be fatal.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#218

Earlier quoted context omitted.

Google One advertises real support for consumer users... but it turns out they can't really so anything but read support docs to you.

Is this a reference to something? I haven't heard much about Google One's support good or bad. The concern I'd have with G-One is that if you lost access to your account, you also aren't a Google One customer, and the support likely won't assist you. Creating a chicken/egg situation.

Not a reference to any story, just a few personal experiences. I had various issues, and they couldn't escalate anything to actually fix them, they just read support docs back to me. It's not like the paid support that gsuite customers get (although I'd be happy to pay more for that if I could).

Re: SIM swap horror story: I've lost decades of data and Google won't help

#219

Earlier quoted context omitted.

Make it something you can pay in advance, then. For a fee, you get marked as a high-risk/high-value account, get the recovery service and risky factors of authentication get extra scrutiny, etc.

You can get extra security from Google for free. https://landing.google.com/advancedprotection/

Patio11 just had an automated loss of access on his phone when enrolling. Lack of support hurts there too.

https://mobile.twitter.com/patio11/status/114040469625693798...

Re: SIM swap horror story: I've lost decades of data and Google won't help

#220
Phone providers, email providers, and banks should provide an option to require in-person verification for account recovery or in the case of phone providers transfer of a number to a different SIM. These events should be infrequent enough that it would be OK if there was a fee for verification.

This might seem impractical for people who live somewhere that the provider doesn't have an office, but it actually isn't. There is a nationwide, readily available mechanism already in place for this. They are called notary publics.

It could work like this:

1. You request account recovery, and pay the fee, and provide your physical contact information.

2. The provider hires a notary public in your area, and sends them a form for you to sign authorizing the account recovery.

3. The notary meets with you, verifies your identity, notarizes your signature on the form, and then lets your provider know that this has successfully completed.

4. Now that the provider knows the request was legitimate, the recovery or transfer can go through.

Post reply on HN