Live data from Hacker News

SIM swap horror story: I've lost decades of data and Google won't help

zdnet.com

251–260 of 303 posts

Re: SIM swap horror story: I've lost decades of data and Google won't help

#251

Google really fails hard in the face of providing support when issues like this occur. The average person has to try various automated account recovery options which, as in the author's case, are readily changeable the moment the account is compromised, rendering them somewhat useless, and then users are out of luck. It's a situation that is mind-boggling. Users as asked to place a significant chunk of their digital…

> I would even not mind something like one-time payments for support calls, for example pay $50 for a service call to get assistance in a case like this. I just can't fathom the "no support" model at all.

Have you considered alternatives that do offer support?

Re: SIM swap horror story: I've lost decades of data and Google won't help

#252

Google really fails hard in the face of providing support when issues like this occur. The average person has to try various automated account recovery options which, as in the author's case, are readily changeable the moment the account is compromised, rendering them somewhat useless, and then users are out of luck. It's a situation that is mind-boggling. Users as asked to place a significant chunk of their digital…

This kind of stuff is horrifying to me and why I willingly pay the Apple Tax. At the end of the day they have stores full of humans I can walk into and tell my sob story to and excellent telephone support.

That is fine but the scam started by reassigning the SIM; something not related to Apple. I am not having enough criminal fantasy but in your Apple World you live in a monoculture...usually this makes it just easier for intruders to make problems.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#253

Earlier quoted context omitted.

My good bank has no physical presence whatsoever. I mean, I presume they operate a call centre somewhere, maybe in Scotland, but I've never seen it. They can reach out and cause things to happen at a distance, but I don't want that used to authenticate me. They used it when I had lost my cards, to cause me to receive a bundle of cash so I could get on with my day just paying cash everywhere. I have a specialized OTP…

I would like to know more about this bank! What bank is it? How did you find it? I've not heard of features similar to this, especially the last part about buying a house.

It's First Direct https://www1.firstdirect.com/

It's a Telephone Bank in the UK, launched in 1989 and I became a customer a year or three after that. Because it doesn't have any branches its call centre staff have to be trained to handle absolutely anything - if they can't fix it then it won't get fixed.

I found it because my father used it, I have no idea why, he was not ordinarily a man to favour technologically sophisticated solutions, he never owned his own email address for example. Maybe as a working man he found it frustrating that other banks were closed after hours? First Direct is never closed, it operates 24/7. I have used other banks for some things, but I've always kept accounts with First Direct because of their truly extraordinary customer service hence I call it the "good bank". I actually know one of their Founders and apparently that commitment to customer service was key to their original vision for the bank, he led a strategy session for the start-up where I work now and it used that vision to give us a worked example. He was Chairman at another start-up I've worked for too. Small world.

For the buying a home part I do mean that I bought it outright by the way, there wasn't a mortgage or anything like that - so that's a lot of money, let's say six figures. I presume the precaution was triggered by the fact that I wanted to move this large sum (almost all the money I had) to an account I'd never sent any money to before. Sounds almost exactly like a scam.

I would _like_ to believe any other bank would have similar protections - but of course I don't buy a home every day, so I have no other examples to compare, and most of my contemporaries have a mortgage so the very large sums aren't involved.

The password when they call me thing was nice, to be honest they didn't proactively set that up. I suggested it off-handedly one day and they were like "Of course, yes, we can set that up". I presume it's not custom, just they didn't explicitly advertise it to me as an option. That happens a lot, I didn't want contactless on my new card recently, and they were like "Yup, of course, done. Replacements for this card will also not have contactless until you call to change that".

Re: SIM swap horror story: I've lost decades of data and Google won't help

#254
> ... enable a requirement that my SIM could not be changed unless someone went into the store with at least one means of physical identification ...

Anyone have experience with this, or heard reports of attacks by means of forged physical ID?

Re: SIM swap horror story: I've lost decades of data and Google won't help

#255

Earlier quoted context omitted.

Thanks for reminding me... again... about this. Why haven't I backed up my gmail data yet? It has been years since I realized I have to do it. Why haven't I done it?

Because it's not easy to automate.

`gmvault` in a cron job works pretty well...

Re: SIM swap horror story: I've lost decades of data and Google won't help

#256
post #38

Earlier quoted context omitted.

Probably because the more barriers you put in the way of scams, social engineering, etc. the harder you make it for people to legitimately get back into their accounts and the more likely it is that you'll instead read stories about how someone "forgot their credentials and lost access to everything in their account and Google won't do anything about it." No opinion on SMS specifically but there are tradeoffs.

Google is a pain as there's no way to talk to a human. I have lost access to an old Gmail account as my phone broke. Without authenticator I can't get in. I can't set up authenticator anew because I don't have the password anymore. I still have same phone and plenty of emails - just no way to get in.

When you set up 2fa with Google they give you a set of backup codes you can use to get back in case you lose access to your phone/authenticator. It's important to store those somewhere safe.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#257

So the same pattern unfolds: Someone trusts faceless uncaring tech companies with all of their most crucial data. Companies get hacked. User's life is crashed. Companies feel nothing and have pathetic "support". "Thankfully", insider access grants privileges. > Thankfully, I have a good friend at $COMPANY who was very concerned with my plight and was able to get $PRIVILEGED_SUPPORT My point is that we have set up the…

Agree.

These two snippets inspired /facepalm:

> While Twitter is a free service, I would still expect some level of assistance for someone who has had the same account for 13 years and can get thousands of people to verify my identity.

'free service' being the operative words, and they can probably trust the user to do all the hard work of maintaining a new account for another 13 years (with associated pageviews) without lifting a finger.

> I made sure to have two-factor authentication (2FA) enabled with this service. It turns out that the 2FA with text messaging sent to a cell phone may be useless when hackers steal your SIM right out from under you.

O RLY. The point of 2FA is that one of those factors is a physical token which cannot be stolen remotely. Anything involving SMS to a phone number is not 2FA and never will be 2FA and anyone claiming otherwise is either an idiot or assumes you are...

Re: SIM swap horror story: I've lost decades of data and Google won't help

#258
Companies should never require SMS as a 2nd factor. It isn't secure. Let's call out names:

* Twitter requires you to enable cell-phone based 2nd factor before they let you enable any other 2nd factor. Luckily in my case their buggy software determined that my cell phone number is "incorrect", so I was never able to.

* Twilio (the authors of Authy!) let you use TOTP codes from Authy in addition to SMS-based 2FA. There is no way to disable the SMS authentication, so your account is never secure.

* Many banks assume that SMS is a secure channel, which it isn't, and force its use as 2FA.

This should get more publicity and companies should be called out on forcing people to use SMS as a 2nd factor. There are many reasons why this is a bad idea, and the story described in the article is just one of many possible attacks.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#260

Earlier quoted context omitted.

You should have emergency backup keys as well printed on real paper. I have a set stored with our important files, and another in my nightstand. Having my phone stolen would be a damnable inconvenience, since that is my second factor -- although not via SIM, but via Google's in-app authentication. But it wouldn't be fatal.

I use andOTP, which is compatible with Google Authenticator and actually allows backing up the private keys (one of the key missing features of Google Authenticator, though maybe they've fixed that).

A good equivalent to andOTP on iOS is OTP Auth (backups, optional cloud syncs, it just works): https://apps.apple.com/us/app/otp-auth/id659877384
Post reply on HN