Live data from Hacker News

SIM swap horror story: I've lost decades of data and Google won't help

zdnet.com

201–210 of 303 posts

Re: SIM swap horror story: I've lost decades of data and Google won't help

#201
post #200

Earlier quoted context omitted.

This is why I panicked when they announced they won't sync Google Photos with Google Drive anymore. With the sync, I can setup one of my computers to constantly download the photos and then copy it onto a local backup and an online backup. If my Google Account gets locked - I'll just copy the photos into something else and move on with my life. They removed that saying it's confusing to users - all the while it was a…

Would you mind elaborating on your iCloud setup to handle this please?

In case you own an iPhone, it's given to you the option to backup your photos to your iCloud account (Apple service bundled into the phone).

Re: SIM swap horror story: I've lost decades of data and Google won't help

#203
post #144

Why is it that the most dramatic stories of people's digital lives being lost/broken usually seem to revolve around a compromised mobile phone number? Mobile phone numbers are not unique (they are recycled) and are terrible security (mobile phone companies are careless). I change mobile numbers at least once a year and most years I end up receiving calls/messages on behalf of the previous owner. I refuse to connect m…

> I change mobile numbers at least once a year and most years I end up receiving calls/messages on behalf of the previous owner.

I had something very similar happen when I got a new number. I kept getting calls for the previous owner from what I assume to have been a bank, a library (for passed-due books no less; left a voice mail), and random people trying to contact this person. Not long thereafter, I started getting text updates from Facebook any time one of their contacts posted something. Facebook fortunately disables this with the text message STOP (IIRC) [1], but it bothered me that a nefarious actor could have passively collected the names of this person's contacts, messages, or more.

Not quite sure what to do, I did end up calling most of them back to inform them they had the wrong number, if they left a voice mail. The calls stopped about a year and a half later, and while I was somewhat annoyed at the time, in retrospect it could have been much worse!

[1] https://www.facebook.com/help/225089214296643

Re: SIM swap horror story: I've lost decades of data and Google won't help

#204
post #12

Anyone who wants to defend themselves, consider using U2F where you can and Google Advanced Protection. I just recently picked up a bluetooth security key because one is needed to log an iPhone into an account using advanced protection; there is no SMS backup loophole. The Titan key bundle comes with a bluetooth and USB key, which is enough to get started, though frankly you probably want a couple additional backup k…

What is your contingency plan for when that physical key is lost, stolen or damaged?

I have about six, one in each computer I regularly use.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#205

> It turns out that the 2FA with text messaging sent to a cell phone may be useless when hackers steal your SIM right out from under you. The most annoying part about this is that Twitter demands your phone number. You can't use another method for 2FA, such as U2F or OTP. I assume it's not at all because they want to authorize you or keep your account safe, but rather because they want to be able to identify you. Use…

> You can't use another method [with Twitter] for 2FA, such as U2F or OTP. Are you sure? * https://www.yubico.com/works-with-yubikey/catalog/twitter/

If you remove your phone number, you’ll eventually be locked out of your account and forced to provide a number. It’s unfortunate.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#206
post #188

Earlier quoted context omitted.

> You can't use another method [with Twitter] for 2FA, such as U2F or OTP. Are you sure? * https://www.yubico.com/works-with-yubikey/catalog/twitter/

They still ban your account without valid non-VOIP phone.

[deleted]

Re: SIM swap horror story: I've lost decades of data and Google won't help

#207
post #126
post #103

Earlier quoted context omitted.

Phones' PINs aren't connected to SIMs. I have to enter my PIN on reboot, even if I removed my SIM. Putting the SIM in a phone without a PIN results in nothing being required. Edit: Thanks for correcting me- I guess my SIM does not have a PIN.

SIM cards themselves can have a PIN attached to them too, usually with a lockout after 3 unsuccessful attempts. The card is supposed to be secure against tampering, but since it's running an OS which receives very little scrutiny and runs lots of legacy tech, there are likely all kinds of exploits to reset / root the SIM and bypass any PIN protection. It's still useful against casual theft though.

While there have been a few very scary hacks that could compromise a currently-unlocked-and-running SIM, I don't think there is anything you can do to a powered-down SIM without the PIN.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#208
As a tech-reviewer I'd assume OP to be more tech-savvy than your average shmoe, yet they kept ALL (literally all) Finanical and generally sensitive information in a central location that easily breached (G-drive) and to top it off used 2FA through SMS for many of their services. If anything this article only discredits the author of any common sense in the tech-space.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#209
post #134
post #89

Earlier quoted context omitted.

How did they get your 4-digit PIN? Don't you have to enter it on every reboot?

SIM PINs aren't enabled by default on iPhones and are independent of your device lock code.

It's not an iPhone thing. It's entirely on your carrier whether or not to enable it on a new SIM.

Re: SIM swap horror story: I've lost decades of data and Google won't help

#210

As a tech-reviewer I'd assume OP to be more tech-savvy than your average shmoe, yet they kept ALL (literally all) Finanical and generally sensitive information in a central location that easily breached (G-drive) and to top it off used 2FA through SMS for many of their services. If anything this article only discredits the author of any common sense in the tech-space.

[deleted]
Post reply on HN