Live data from Hacker News

Google Fi seemingly affected by latest T-Mobile data breach

9to5google.com

21–30 of 88 posts

Re: Google Fi seemingly affected by latest T-Mobile data breach

#21
post #9
post #5

Not everyone got this version of the notice. Here's a reddit user who posted [1] that they were SIM swapped: > Additionally, on January 1, 2023 for about 1 hour 48 minutes, your mobile phone service was transferred from your SIM card to another SIM card. During the time of this temporary transfer, the unauthorized access could have involved the use of your phone number to send and receive phone calls and text message…

Oof, that's not good. As a Fi user, I'm pretty angry at the moment even though I got the other version of the notice. That's because one of the main reasons I was using Fi in the first place was the perceived protection against sim swapping, via a super locked down special purpose Google account and the apparent inability of T-Mobile CSRs to access Fi customer data. The first thing I thought upon reading the notice w…

The why is obvious.

People will lose their 2FA. It's a fact of life. Lost keys with your yubikey. Broken phone without a backup of your totp. Etc.

After that, how do you prove that someone owns their account?

Send a photocopy of your passport? No way to edit a picture, right?

Answer some security questions, which you certainly forgot the answer to. And people are likely using the same questions with the same answer on many sites.

Tell them tough luck?

The problem is there isn't a good answer for the most common failure mode. SMS 2FA isn't perfect, but it is accessible to nearly everyone and delegates ownership proof to the telephone company.

Re: Google Fi seemingly affected by latest T-Mobile data breach

#22
post #2

A reasonable headline could state "Google Fi essentially not affected by latest T-Mobile data breach". Look at the data "breached": > limited data including when your account was activated, data about your mobile service plan, SIM card serial number, and active or inactive account status. > It does not contain your name, date of birth, email address, payment card information, social security number or tax IDs, driver…

[flagged]

Oof. Trying to be a grammar pedant on the internet and getting it wrong. Big L there, homes.

Re: Google Fi seemingly affected by latest T-Mobile data breach

#23
post #6

The same probably goes for other MVNO carriers such as Mint and Ting. The PII and billing data is with the MVNO carriers. I buy my SIM cards anonymously. I never use cellular near my house and only use it for data over a VPN. So it would not affect me if all of their data was breached.

>The same probably goes for other MVNO carriers such as Mint and Ting. The PII and billing data is with the MVNO carriers. Are you sure? In the previous T-Mo breach Ting claimed the opposite. https://help.ting.com/hc/en-us/community/posts/4405384603291... >the kind of Ting Mobile customer data at issue in this data breach is not stored on T-Mobile servers. Ting Mobile holds its own customer database on our own server…

Thanks. I was not sure. MVNO contracts could differ. This gives me more reason to hide my identity by using SIM cards carefully.

Re: Google Fi seemingly affected by latest T-Mobile data breach

#24
post #6

The same probably goes for other MVNO carriers such as Mint and Ting. The PII and billing data is with the MVNO carriers. I buy my SIM cards anonymously. I never use cellular near my house and only use it for data over a VPN. So it would not affect me if all of their data was breached.

What threat model does this help with?

Re: Google Fi seemingly affected by latest T-Mobile data breach

#25

Earlier quoted context omitted.

Lol this is not the same with most people. Pretty incredible if true. Timing attacks are pretty powerful though. Only one person has likely been to all the same places at you at the same time over the past week.

I don't have a regular movement pattern and only activate the SIM when needed. I also rotate SIM's with my partner to confuse things more. We are part of a budding trend.

If you really want to be safe you should eat your SIM card.

https://youtu.be/wxJkLKjdMcc

Re: Google Fi seemingly affected by latest T-Mobile data breach

#26
post #21
post #9

Earlier quoted context omitted.

Oof, that's not good. As a Fi user, I'm pretty angry at the moment even though I got the other version of the notice. That's because one of the main reasons I was using Fi in the first place was the perceived protection against sim swapping, via a super locked down special purpose Google account and the apparent inability of T-Mobile CSRs to access Fi customer data. The first thing I thought upon reading the notice w…

The why is obvious. People will lose their 2FA. It's a fact of life. Lost keys with your yubikey. Broken phone without a backup of your totp. Etc. After that, how do you prove that someone owns their account? Send a photocopy of your passport? No way to edit a picture, right? Answer some security questions, which you certainly forgot the answer to. And people are likely using the same questions with the same answer o…

Solution is multiple yubikeys or printing out backup codes.

Re: Google Fi seemingly affected by latest T-Mobile data breach

#27
post #21
post #9

Earlier quoted context omitted.

Oof, that's not good. As a Fi user, I'm pretty angry at the moment even though I got the other version of the notice. That's because one of the main reasons I was using Fi in the first place was the perceived protection against sim swapping, via a super locked down special purpose Google account and the apparent inability of T-Mobile CSRs to access Fi customer data. The first thing I thought upon reading the notice w…

The why is obvious. People will lose their 2FA. It's a fact of life. Lost keys with your yubikey. Broken phone without a backup of your totp. Etc. After that, how do you prove that someone owns their account? Send a photocopy of your passport? No way to edit a picture, right? Answer some security questions, which you certainly forgot the answer to. And people are likely using the same questions with the same answer o…

I have used both. During that time I've lost access to SMS due to my phone breaking (twice), I have lost permanent access to online banking because the bank will not accept an international number. I came extremely close to losing access to my entire Google account because I use Fi and you need to sign into Google to activate it on your phone, but you need to be able to receive SMS to sign in to Google.

Meanwhile, I have multiple yubikeys that are as hard to lose or break as a house key. Google is kind of the only site that supports hardware tokens, but you can add multiple to your account. I can't think of a single site that allows multiple phone numbers for SMS 2fa.

Re: Google Fi seemingly affected by latest T-Mobile data breach

#28
post #6

The same probably goes for other MVNO carriers such as Mint and Ting. The PII and billing data is with the MVNO carriers. I buy my SIM cards anonymously. I never use cellular near my house and only use it for data over a VPN. So it would not affect me if all of their data was breached.

What threat model does this help with?

Phone carrier metadata tracking for https and MITM and advertisement insertion into non-secured web pages.

Re: Google Fi seemingly affected by latest T-Mobile data breach

#29
post #15

Earlier quoted context omitted.

> only use it for data over a VPN Unless you run this yourself, I don't understand why you nor anyone thinks that adds to their data integrity? VPNs can, have, and are the subject of break-ins and have their own agenda and or government oversight. People think that VPNs are this magical black box that makes you secure and private, because the YouTube ads told everyone so, the reality is that you are just adding an ex…

In the context of not trusting your ISP (the mobile provider in this case) a VPN provides a lot of security. You aren’t “adding an extra point of trust or potential failure”, you are choosing to trust your VPN provider instead of your ISP.

VPNs still have massive problems with network diversity. They often rely on a tiny subset of transit providers, usually just Cogent/HE/Telia and some straight up all run on the same network, usually M247. While a carrier like Comcast has thousands of peering agreements and much more diverse routing. This means all traffic coming out of a VPN is viewable by a tiny group of network providers.

Sure, I would probably trust Cogent over Comcast, but the current state of the VPN market seems very stagnant in actually diverse network routing.

It's really hard to recommend a VPN for people who are actually privacy conscious simply because you're moving your data to a handful of transit providers that aren't put under nearly as much scrutiny as a normal consumer ISP.

Re: Google Fi seemingly affected by latest T-Mobile data breach

#30

Earlier quoted context omitted.

Lol this is not the same with most people. Pretty incredible if true. Timing attacks are pretty powerful though. Only one person has likely been to all the same places at you at the same time over the past week.

I don't have a regular movement pattern and only activate the SIM when needed. I also rotate SIM's with my partner to confuse things more. We are part of a budding trend.

[flagged]
Post reply on HN