Live data from Hacker News

Google Fi seemingly affected by latest T-Mobile data breach

9to5google.com

1–10 of 88 posts

Re: Google Fi seemingly affected by latest T-Mobile data breach

#2
A reasonable headline could state "Google Fi essentially not affected by latest T-Mobile data breach". Look at the data "breached":

> limited data including when your account was activated, data about your mobile service plan, SIM card serial number, and active or inactive account status.

> It does not contain your name, date of birth, email address, payment card information, social security number or tax IDs, driver’s license or other form of government ID, or financial account information, passwords or PINs that you may use for Google Fi, or the contents of any SMS messages or calls.

I mean, that's almost the minimum amount of data T-Mobile has to have to provide the service to Google Fi customers, and nothing else. The actual customer data is probably stored at Google, and is perfectly safe. The chances of someone being able to use the leaked data in a nefarious way seem practically nil.

Re: Google Fi seemingly affected by latest T-Mobile data breach

#5
Not everyone got this version of the notice. Here's a reddit user who posted [1] that they were SIM swapped:

> Additionally, on January 1, 2023 for about 1 hour 48 minutes, your mobile phone service was transferred from your SIM card to another SIM card. During the time of this temporary transfer, the unauthorized access could have involved the use of your phone number to send and receive phone calls and text messages. Despite the SIM transfer, your voicemail could not have been accessed. We have restored Google Fi service to your SIM card.

[1]: https://old.reddit.com/r/GoogleFi/comments/10pjtie/google_fi...

Re: Google Fi seemingly affected by latest T-Mobile data breach

#6
The same probably goes for other MVNO carriers such as Mint and Ting. The PII and billing data is with the MVNO carriers.

I buy my SIM cards anonymously. I never use cellular near my house and only use it for data over a VPN. So it would not affect me if all of their data was breached.

Re: Google Fi seemingly affected by latest T-Mobile data breach

#7
post #6

The same probably goes for other MVNO carriers such as Mint and Ting. The PII and billing data is with the MVNO carriers. I buy my SIM cards anonymously. I never use cellular near my house and only use it for data over a VPN. So it would not affect me if all of their data was breached.

Lol this is not the same with most people. Pretty incredible if true. Timing attacks are pretty powerful though. Only one person has likely been to all the same places at you at the same time over the past week.

Re: Google Fi seemingly affected by latest T-Mobile data breach

#8
post #6

The same probably goes for other MVNO carriers such as Mint and Ting. The PII and billing data is with the MVNO carriers. I buy my SIM cards anonymously. I never use cellular near my house and only use it for data over a VPN. So it would not affect me if all of their data was breached.

> only use it for data over a VPN

Unless you run this yourself, I don't understand why you nor anyone thinks that adds to their data integrity? VPNs can, have, and are the subject of break-ins and have their own agenda and or government oversight.

People think that VPNs are this magical black box that makes you secure and private, because the YouTube ads told everyone so, the reality is that you are just adding an extra point of trust or potential failure. The needle has barely moved.

All while making performance, in particular latency, worse.

Re: Google Fi seemingly affected by latest T-Mobile data breach

#9
post #5

Not everyone got this version of the notice. Here's a reddit user who posted [1] that they were SIM swapped: > Additionally, on January 1, 2023 for about 1 hour 48 minutes, your mobile phone service was transferred from your SIM card to another SIM card. During the time of this temporary transfer, the unauthorized access could have involved the use of your phone number to send and receive phone calls and text message…

Oof, that's not good. As a Fi user, I'm pretty angry at the moment even though I got the other version of the notice. That's because one of the main reasons I was using Fi in the first place was the perceived protection against sim swapping, via a super locked down special purpose Google account and the apparent inability of T-Mobile CSRs to access Fi customer data. The first thing I thought upon reading the notice was usefulness for sim swapping, and my heart fell upon reading your comment.

Good reminder that SMS 2fa fucking sucks and so do the institutions that insist on it, especially those that offer other forms of 2fa but treat SMS as a fallback (why why why why why).

Re: Google Fi seemingly affected by latest T-Mobile data breach

#10
post #6

The same probably goes for other MVNO carriers such as Mint and Ting. The PII and billing data is with the MVNO carriers. I buy my SIM cards anonymously. I never use cellular near my house and only use it for data over a VPN. So it would not affect me if all of their data was breached.

> only use it for data over a VPN Unless you run this yourself, I don't understand why you nor anyone thinks that adds to their data integrity? VPNs can, have, and are the subject of break-ins and have their own agenda and or government oversight. People think that VPNs are this magical black box that makes you secure and private, because the YouTube ads told everyone so, the reality is that you are just adding an ex…

We concentrated in one place the internet traffic of people who care enough about privacy that they are willing to pay for an extra service. What could go wrong!?
Post reply on HN