Live data from Hacker News

SIM swap horror story: I've lost decades of data and Google won't help

zdnet.com

281–290 of 303 posts

Re: SIM swap horror story: I've lost decades of data and Google won't help

#281

Earlier quoted context omitted.

This is why I panicked when they announced they won't sync Google Photos with Google Drive anymore. With the sync, I can setup one of my computers to constantly download the photos and then copy it onto a local backup and an online backup. If my Google Account gets locked - I'll just copy the photos into something else and move on with my life. They removed that saying it's confusing to users - all the while it was a…

FWIW, I use syncthing for this exact use case.

SyncThing is fantastic, it's really solid and always just works.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#282
It’s probably a good time to remind people complaining that there is no Google support to call:

You are not their customer. You are their product.

This is quite literally true. They only have to care for us cattle enough to keep us as good products.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#283
post #268

> ... enable a requirement that my SIM could not be changed unless someone went into the store with at least one means of physical identification ... Anyone have experience with this, or heard reports of attacks by means of forged physical ID?

How to Fight Mobile Number Port-out Scams https://krebsonsecurity.com/2018/02/how-to-fight-mobile-numb... " T-Mobile suggests adding its port validation feature to all accounts. To do this, call 611 from your T-Mobile phone or dial 1-800-937-8997 from any phone. The T-Mobile customer care representative will ask you to create a 6-to-15-digit passcode that will be added to your account. "

And then I forget/lose my 15 digit passcode, then what? Either there is a retrieval method that makes the whole thing irrelevant, or else I've replaced one catastrophe with another to no purpose.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#284
Anyone know if Google Voice numbers have more protection from the SIM attack? I would assume that those numbers are hard to port out anywhere given their usage, right? Are mobile numbers part of a separate pool of numbers with different rules on porting?

Re: SIM swap horror story: I've lost decades of data and Google won't help

#285

If you haven't yet, remove your telephone number as a recovery option for your Gmail account. And also, why can't US fix the shit that is transferring SIM cards? In the UK you can request a SIM transfer code but it takes at least a few days - there's plenty of time to catch it and stop it before someone transfers your SIM. Why can't American operators do the same? Just say "you have received your request, please wait…

There's no such thing as a "SIM transfer code" in the UK. SIM swap scams are a thing here too : https://www.bbc.co.uk/news/business-46047714

Re: SIM swap horror story: I've lost decades of data and Google won't help

#286

I don't understand how the attacker got access to his Google account just from his phone number? Was his password "password"?

You can just say you forgot your password and they’ll send you a text message with a code to reset the password if you’ve registered a number with that account.

Oh yeah, that's a terrible security practice.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#287
post #187

In the space of the afternoon after reading this article, I removed SMS 2FA from all my accounts, installed Authy, added all my accounts to it, found out Authy is also insecure[0], reconfigured it to be less insecure, and basically despaired. My solution going forward will be to spend all of my money each month so there's nothing to steal, and have a terrible reputation online that therefore can't be ruined. [0] http…

After reading a similar article on HN a year ago, I too decided to use Authy but the realized that it was vulnerable to the same methods. I eventually decided to use andOTP[1].

While it doesn't automatically sync across devices, it does allow you to create backups[2] which can be encrypted with AES or your PGP key. Just store this in Dropbox/Drive/Box and offline storage and you're good to go.

[1] https://github.com/andOTP/andOTP/blob/master/README.md [2] https://raw.githubusercontent.com/flocke/andOTP/master/asset...

Re: SIM swap horror story: I've lost decades of data and Google won't help

#288
post #91
post #59

Earlier quoted context omitted.

SMS 2FA is fine. 2FA adds another layer on top of your password. The second factor doesn’t have to be particularly secure to make you safer. The problem is SMS account recovery , which is a really bad idea.

> The problem is SMS account recovery, which is a really bad idea. The problem is that a lot of services tie the two together. Often one implies the other. Even if it doesn't, though, it's also easier to social engineer -- "look! I have access to the 2fa phone number! I just can't access my password manager!"

Companies do that, but they shouldn't call it 2FA at that point as it is no longer a _second_ factor: it has become the primary factor.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#289

Google really fails hard in the face of providing support when issues like this occur. The average person has to try various automated account recovery options which, as in the author's case, are readily changeable the moment the account is compromised, rendering them somewhat useless, and then users are out of luck. It's a situation that is mind-boggling. Users as asked to place a significant chunk of their digital…

There’s also another bad side effect of Google. Google makes and gives away stuff for free and one of the reasons they do it is because they run a lean operation. They don’t provide any kind of support. Let’s say someone want to start a new company that provides all the same features of Google and provide solid support - there’s no way they can do it for free. Or even if it’s a reasonable price, people are going to p…

> kills any possible paid service in the domains they operate.

I can think of paid services that compete in the domains google operates in. Fastmail is an easy one.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#290
post #35
post #33

Earlier quoted context omitted.

Why not "defend" yourself by not relying on gmail? It's not exactly the first time this has happened.

What’s better? Serious question. Very few companies spend as much on security as Google. You have to do your part and configure something like Advanced Protection, but if someone’s going to go to all the effort listed in the article, which provider would be a better bet?

It's not like email providers get hacked all the time. Individual email accounts do get hacked.

Find an email provider that provides decent support, i.e. you can call and talk to a real person. Make sure they support 2FA (ideally the non SIM variant). Also recovery tokens that you can write down and stuff like that.

Personally I run my own mail server but I understand that's not everybody's cup of tea.

Post reply on HN