Google really fails hard in the face of providing support when issues like this occur. The average person has to try various automated account recovery options which, as in the author's case, are readily changeable the moment the account is compromised, rendering them somewhat useless, and then users are out of luck. It's a situation that is mind-boggling. Users as asked to place a significant chunk of their digital…
This is why I panicked when they announced they won't sync Google Photos with Google Drive anymore. With the sync, I can setup one of my computers to constantly download the photos and then copy it onto a local backup and an online backup. If my Google Account gets locked - I'll just copy the photos into something else and move on with my life. They removed that saying it's confusing to users - all the while it was a…
SIM swap horror story: I've lost decades of data and Google won't help
231–240 of 303 posts
Re: SIM swap horror story: I've lost decades of data and Google won't help
#232Earlier quoted context omitted.
Why doesn't Google get rid of SMS recovery completely? It's a huge security flaw that can be easily exploited.
When you first enable 2FA with Google you have to do SMS (at least that was the requirement last time I did it). However, once you've defined an alternative 2FA method (Google auth, u2f key, etc) then you can remove the SMS method completely. Believe it or not banks are really bad at security. They are so bad at it that they don't even realize how bad at it they are. But the banks all copy from each other so "what th…
I don't remember that ever being the case, either when Google first launched Google Authenticator and 2FA (when I pretty soon after set it up) or when I later went through the setup process for my work account at my current job (a couple years ago).
Re: SIM swap horror story: I've lost decades of data and Google won't help
#233Earlier quoted context omitted.
Why not "defend" yourself by not relying on gmail? It's not exactly the first time this has happened.
The article doesn't say if the user had two-factor authentication set up. I guess it's implied they used SMS as the second factor. This would happen with any email provider. So the fix isn't changing email provider, it's using a more secure second factor, e.g. U2F.
Re: SIM swap horror story: I've lost decades of data and Google won't help
#234A few suggestions: 1) Call your cellphone carrier and ask to set up a password/PIN to be used for when you call into the customer service phone number. 2) Consider your phone number and SIM card insecure. The phone carriers are ignoring the SIM swap problem even though they know how much damage it's causing. Give your phone number to as few companies as possible. Phone services such as Google Voice work without a SIM…
> Call your cellphone carrier and ask to set up a password/PIN Note that, at least for TMobile, AT&T, and Verizon, the password/PIN is presented to the CSR in plaintext (as they verify the pin over the phone verbally). I'd assumed they'd transfer to some pin-capture applet to verify, but nope. > Use an authentication app, such as Google Authenticator If you decide on Google Authenticator, make sure you scan the barco…
Re: SIM swap horror story: I've lost decades of data and Google won't help
#235* all emergency/account recovery info changed
* Person contacts shortly thereafter claiming account hack
I lost a legacy skype account recently. It had had no email attached to it, so the hacker was able to add theirs and get notified whenever I got back into the account. There was no way to remove their email or add new security mechanisms without waiting 24 hours, so I had no way to keep them from resetting the password.
The account was shut down for spam not long after. As far as I could tell there was no way to effectively reach microsoft about this, despite being a paying office 365 customer. They had a security chat but it was a deadend, and slow.
Re: SIM swap horror story: I've lost decades of data and Google won't help
#236This is a good place to remind everyone of Google Takeout [1]. Back up all of your data. Don't let this horror story happen to you. [1] https://takeout.google.com/settings/takeout
Re: SIM swap horror story: I've lost decades of data and Google won't help
#237I have all this in my gmail also, but my mail downloads to my computer (I use Mail on my Mac). My Mail application data in turn backs up to a few backup drives, so I have this data in several places.
Do people use gmail without having a copy stored anywhere else? I totally get that this guy has been screwed many different ways, including by Google, but it seems unwise to not have a backup copy of your mail anywhere.
Re: SIM swap horror story: I've lost decades of data and Google won't help
#238This is a good place to remind everyone of Google Takeout [1]. Back up all of your data. Don't let this horror story happen to you. [1] https://takeout.google.com/settings/takeout
Thanks for the reminder--I've done it several times in the past, but it wasn't a scheduled thing at all. There's a new checkbox in takeout that lets you schedule a backup every 2 months (and then presumably you'll get an email when you need to download it). Does anyone else have issues with takeout failing with "unknown error occurred" if you use the default of selecting all products? I have to manually create multip…
Re: SIM swap horror story: I've lost decades of data and Google won't help
#239Earlier quoted context omitted.
It depends on your threat level. If you're just trying to avoid phishing, it's great, something like 99.9% effective. However, if you're worried you'll be targeted, where someone will go through the effort to do this to you specifically, then it's not a good choice.
2FA does not fully protect you against phishing. The attacker can just passthrough all credentials including your 2FA code. It limits the attack to a time window and any further security sensitive changes that require 2FA may be protected unless the user naively re-enters their code.
Or in more detail, the credentials aren't human readable and are per-FQDN, so when you visit badguy.example thinking it's goodguy.example, your Security Key will cheerfully hand over valid credentials for badguy.example, but there is no way to give them credentials for goodguy.example because that's not where you are.
Hence that 100% score on Google's page.
Re: SIM swap horror story: I've lost decades of data and Google won't help
#240In India to port a sim you have to first send a sms and would receive a verification number which is valid for a month or something.