Live data from Hacker News

SIM swap horror story: I've lost decades of data and Google won't help

zdnet.com

261–270 of 303 posts

Re: SIM swap horror story: I've lost decades of data and Google won't help

#261
post #49

Unlike what the OP stated, the key is NOT to list you phone number as an SMS 2FA recovery option. Only use the non-SMS options (e.g. app-based recovery, Google Authenticator, recovery codes). Adding SMS as an option makes your account less secure, not more. Unfortunately, most sites do not allow you to turn off SMS recovery even if they offer other 2FA options. Security is only as strong as the weakest link, and SMS…

The problem lies in that Google Authenticator is tied to a device, so if you upgrade it or lose it, you’re f’d. I also doubt many use/print recovery codes, and if they do, good luck finding them 7 years later. Overall the situation isn’t great.

I encountered the similar problem the last time I upgraded. There are alternatives to Google Authenticator that offer backups and cloud syncs while maintaining security. andOTP on Android and OTP Auth on iOS. https://play.google.com/store/apps/details?id=org.shadowice.... https://apps.apple.com/us/app/otp-auth/id659877384

Re: SIM swap horror story: I've lost decades of data and Google won't help

#262

Earlier quoted context omitted.

The problem lies in that Google Authenticator is tied to a device, so if you upgrade it or lose it, you’re f’d. I also doubt many use/print recovery codes, and if they do, good luck finding them 7 years later. Overall the situation isn’t great.

I still have my Google Account recovery codes in my wallet that I first generated in 2011.

Better not lose your wallet!

When you’re at Google scale, all of these methods have real world flaws.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#263
post #258

Companies should never require SMS as a 2nd factor. It isn't secure. Let's call out names: * Twitter requires you to enable cell-phone based 2nd factor before they let you enable any other 2nd factor. Luckily in my case their buggy software determined that my cell phone number is "incorrect", so I was never able to. * Twilio (the authors of Authy!) let you use TOTP codes from Authy in addition to SMS-based 2FA. There…

Its because all of these companies are cheap and don't want to deal with the customer support cost of people who lose a virtual/physical MFA device. Instead, they treat virtual/physical MFA like a convenience feature that their customers keep whining about. But, if you've got that SMS on backup, then who cares if you lose the MFA; just use your phone, security be damned.

1Password is also guilty of this in a different way: They won't let you register a U2F physical security key unless you also have a virtual security key on the account.

This is ridiculously simple. I'll spell it out:

1) Offer Virtual, U2F, and SMS-based multi-factor authentication. SMS is still useful for convenience on platforms which pose less of a security risk to your digital life.

2) Don't gatekeep methods of multi-factor authentication behind others.

3) Allow multiple devices for each method of multi-factor authentication, especially physical U2F keys.

4) Offer backup codes.

5) Offer an Enhanced Lockdown option, whereby customer support account recovery is irrevocably impossible in the event of lost multi-factor.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#264

Earlier quoted context omitted.

Make it something you can pay in advance, then. For a fee, you get marked as a high-risk/high-value account, get the recovery service and risky factors of authentication get extra scrutiny, etc.

You can get extra security from Google for free. https://landing.google.com/advancedprotection/

Not exactly free, because you must buy a couple of hardware tokens. Fifty dollars when bought from google. But free besides that.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#265
post #241

Earlier quoted context omitted.

This is why I panicked when they announced they won't sync Google Photos with Google Drive anymore. With the sync, I can setup one of my computers to constantly download the photos and then copy it onto a local backup and an online backup. If my Google Account gets locked - I'll just copy the photos into something else and move on with my life. They removed that saying it's confusing to users - all the while it was a…

Where did they announce that? I still have that setting enabled, and I'm using it for backing up exactly the same way you described, so I really hope this doesn't just get magically turned off someday.

Google Photos will stop syncing to Drive on July 10, 2019 https://gsuiteupdates.googleblog.com/2019/06/google-photos-d...

HN discussion: https://news.ycombinator.com/item?id=20166131

Re: SIM swap horror story: I've lost decades of data and Google won't help

#266
post #144

Why is it that the most dramatic stories of people's digital lives being lost/broken usually seem to revolve around a compromised mobile phone number? Mobile phone numbers are not unique (they are recycled) and are terrible security (mobile phone companies are careless). I change mobile numbers at least once a year and most years I end up receiving calls/messages on behalf of the previous owner. I refuse to connect m…

Because every time you login to gmail without a phone number there's a big "add your phone number for super security!!" pop up on the screen. People do what the google tells them to do.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#267
post #73

Earlier quoted context omitted.

2FA does not fully protect you against phishing. The attacker can just passthrough all credentials including your 2FA code. It limits the attack to a time window and any further security sensitive changes that require 2FA may be protected unless the user naively re-enters their code.

U2F/ WebAuthn credentials can't be passed through. Or in more detail, the credentials aren't human readable and are per-FQDN, so when you visit badguy.example thinking it's goodguy.example, your Security Key will cheerfully hand over valid credentials for badguy.example, but there is no way to give them credentials for goodguy.example because that's not where you are. Hence that 100% score on Google's page.

Meant to say TOTP or SMS 2FA.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#268

> ... enable a requirement that my SIM could not be changed unless someone went into the store with at least one means of physical identification ... Anyone have experience with this, or heard reports of attacks by means of forged physical ID?

How to Fight Mobile Number Port-out Scams https://krebsonsecurity.com/2018/02/how-to-fight-mobile-numb...

"T-Mobile suggests adding its port validation feature to all accounts. To do this, call 611 from your T-Mobile phone or dial 1-800-937-8997 from any phone. The T-Mobile customer care representative will ask you to create a 6-to-15-digit passcode that will be added to your account."

Re: SIM swap horror story: I've lost decades of data and Google won't help

#269
“Maybe I was naive”

Why don’t I take my entire life and give it to tech companies? That seems like a good idea! I’ll just upload all my tax returns and other critical documents to the cloud because the cloud is well thought out and rock solid. I know this because software of all kinds is known to be well thought out and written in a pragmatic and thoughtful manner. There have never been instances of people exploiting flaws in software or the companies that maintain software. The web is not broken and is definitely not a precarious mountain of turds held together with scotch tape. The web is rock solid and I will trust it with my very life. My whole career depends on a twitter account and i have never tried to lessen my reliance on a single twitter account. Having my entire career depend on a twitter account is a safe and prudent thing to do. I have children.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#270

Earlier quoted context omitted.

It’s $20/year to get 100GB of space for GoogleOne. Worth it so that you have a paid account with support options.

The author mentions that they are a paying customer.

Google One has support, it's pretty much the only button in the UI when you go there.

EDIT: actually it looks like the support might need to be reached from within the account, so that's still a major problem when you can't get in at all.

Post reply on HN