Unlike what the OP stated, the key is NOT to list you phone number as an SMS 2FA recovery option. Only use the non-SMS options (e.g. app-based recovery, Google Authenticator, recovery codes). Adding SMS as an option makes your account less secure, not more. Unfortunately, most sites do not allow you to turn off SMS recovery even if they offer other 2FA options. Security is only as strong as the weakest link, and SMS…
The problem lies in that Google Authenticator is tied to a device, so if you upgrade it or lose it, you’re f’d. I also doubt many use/print recovery codes, and if they do, good luck finding them 7 years later. Overall the situation isn’t great.
SIM swap horror story: I've lost decades of data and Google won't help
261–270 of 303 posts
Re: SIM swap horror story: I've lost decades of data and Google won't help
#262Earlier quoted context omitted.
The problem lies in that Google Authenticator is tied to a device, so if you upgrade it or lose it, you’re f’d. I also doubt many use/print recovery codes, and if they do, good luck finding them 7 years later. Overall the situation isn’t great.
I still have my Google Account recovery codes in my wallet that I first generated in 2011.
When you’re at Google scale, all of these methods have real world flaws.
Re: SIM swap horror story: I've lost decades of data and Google won't help
#263Companies should never require SMS as a 2nd factor. It isn't secure. Let's call out names: * Twitter requires you to enable cell-phone based 2nd factor before they let you enable any other 2nd factor. Luckily in my case their buggy software determined that my cell phone number is "incorrect", so I was never able to. * Twilio (the authors of Authy!) let you use TOTP codes from Authy in addition to SMS-based 2FA. There…
1Password is also guilty of this in a different way: They won't let you register a U2F physical security key unless you also have a virtual security key on the account.
This is ridiculously simple. I'll spell it out:
1) Offer Virtual, U2F, and SMS-based multi-factor authentication. SMS is still useful for convenience on platforms which pose less of a security risk to your digital life.
2) Don't gatekeep methods of multi-factor authentication behind others.
3) Allow multiple devices for each method of multi-factor authentication, especially physical U2F keys.
4) Offer backup codes.
5) Offer an Enhanced Lockdown option, whereby customer support account recovery is irrevocably impossible in the event of lost multi-factor.
Re: SIM swap horror story: I've lost decades of data and Google won't help
#264Earlier quoted context omitted.
Make it something you can pay in advance, then. For a fee, you get marked as a high-risk/high-value account, get the recovery service and risky factors of authentication get extra scrutiny, etc.
You can get extra security from Google for free. https://landing.google.com/advancedprotection/
Re: SIM swap horror story: I've lost decades of data and Google won't help
#265Earlier quoted context omitted.
This is why I panicked when they announced they won't sync Google Photos with Google Drive anymore. With the sync, I can setup one of my computers to constantly download the photos and then copy it onto a local backup and an online backup. If my Google Account gets locked - I'll just copy the photos into something else and move on with my life. They removed that saying it's confusing to users - all the while it was a…
Where did they announce that? I still have that setting enabled, and I'm using it for backing up exactly the same way you described, so I really hope this doesn't just get magically turned off someday.
HN discussion: https://news.ycombinator.com/item?id=20166131
Re: SIM swap horror story: I've lost decades of data and Google won't help
#266Why is it that the most dramatic stories of people's digital lives being lost/broken usually seem to revolve around a compromised mobile phone number? Mobile phone numbers are not unique (they are recycled) and are terrible security (mobile phone companies are careless). I change mobile numbers at least once a year and most years I end up receiving calls/messages on behalf of the previous owner. I refuse to connect m…
Re: SIM swap horror story: I've lost decades of data and Google won't help
#267Earlier quoted context omitted.
2FA does not fully protect you against phishing. The attacker can just passthrough all credentials including your 2FA code. It limits the attack to a time window and any further security sensitive changes that require 2FA may be protected unless the user naively re-enters their code.
U2F/ WebAuthn credentials can't be passed through. Or in more detail, the credentials aren't human readable and are per-FQDN, so when you visit badguy.example thinking it's goodguy.example, your Security Key will cheerfully hand over valid credentials for badguy.example, but there is no way to give them credentials for goodguy.example because that's not where you are. Hence that 100% score on Google's page.
Re: SIM swap horror story: I've lost decades of data and Google won't help
#268> ... enable a requirement that my SIM could not be changed unless someone went into the store with at least one means of physical identification ... Anyone have experience with this, or heard reports of attacks by means of forged physical ID?
"T-Mobile suggests adding its port validation feature to all accounts. To do this, call 611 from your T-Mobile phone or dial 1-800-937-8997 from any phone. The T-Mobile customer care representative will ask you to create a 6-to-15-digit passcode that will be added to your account."
Re: SIM swap horror story: I've lost decades of data and Google won't help
#269Why don’t I take my entire life and give it to tech companies? That seems like a good idea! I’ll just upload all my tax returns and other critical documents to the cloud because the cloud is well thought out and rock solid. I know this because software of all kinds is known to be well thought out and written in a pragmatic and thoughtful manner. There have never been instances of people exploiting flaws in software or the companies that maintain software. The web is not broken and is definitely not a precarious mountain of turds held together with scotch tape. The web is rock solid and I will trust it with my very life. My whole career depends on a twitter account and i have never tried to lessen my reliance on a single twitter account. Having my entire career depend on a twitter account is a safe and prudent thing to do. I have children.
Re: SIM swap horror story: I've lost decades of data and Google won't help
#270Earlier quoted context omitted.
It’s $20/year to get 100GB of space for GoogleOne. Worth it so that you have a paid account with support options.
The author mentions that they are a paying customer.
EDIT: actually it looks like the support might need to be reached from within the account, so that's still a major problem when you can't get in at all.