Live data from Hacker News

Google Fi seemingly affected by latest T-Mobile data breach

9to5google.com

31–40 of 88 posts

Re: Google Fi seemingly affected by latest T-Mobile data breach

#31
post #15

Earlier quoted context omitted.

> only use it for data over a VPN Unless you run this yourself, I don't understand why you nor anyone thinks that adds to their data integrity? VPNs can, have, and are the subject of break-ins and have their own agenda and or government oversight. People think that VPNs are this magical black box that makes you secure and private, because the YouTube ads told everyone so, the reality is that you are just adding an ex…

In the context of not trusting your ISP (the mobile provider in this case) a VPN provides a lot of security. You aren’t “adding an extra point of trust or potential failure”, you are choosing to trust your VPN provider instead of your ISP.

HTTPS already provides the same protection. VPN doesn't add anything for that.

About the only meaningful feature VPN provides is presenting a different IP address to the server.

VPN provides negligible extra security for most people, while adding extra exposure.

Re: Google Fi seemingly affected by latest T-Mobile data breach

#33
post #26
post #21

Earlier quoted context omitted.

The why is obvious. People will lose their 2FA. It's a fact of life. Lost keys with your yubikey. Broken phone without a backup of your totp. Etc. After that, how do you prove that someone owns their account? Send a photocopy of your passport? No way to edit a picture, right? Answer some security questions, which you certainly forgot the answer to. And people are likely using the same questions with the same answer o…

Solution is multiple yubikeys or printing out backup codes.

How are you handling multiple Yubikeys? I'm doing it personally and it's so annoying that I can't imagine recommending this to anyone else. Since I'd hate to lose access to everything if my house burns down, I keep a key outside of the home. Of course, for that key to be useful, I need to update it whenever I use my key on a new site/service. Dropping everything to go fetch my key is inconvenient, so I keep multiple keys in the house. That way I can add two keys to a service and have a local backup in case one breaks. But, then I need to remember to actually add the off-site key to the account as well.

Maybe I should just round-robin the off-site key. It's just tedious to keep track of what's been registered with which key and making sure they're all in sync. I really wish there were a secure way to simply have a key backup.

Not to mention, this is kind of expensive and also non-obvious as Yubikey primarily sells single keys. I'd love to see wider adoption, but can't see the general population putting up with this.

Re: Google Fi seemingly affected by latest T-Mobile data breach

#34
post #26

Earlier quoted context omitted.

Solution is multiple yubikeys or printing out backup codes.

How are you handling multiple Yubikeys? I'm doing it personally and it's so annoying that I can't imagine recommending this to anyone else. Since I'd hate to lose access to everything if my house burns down, I keep a key outside of the home. Of course, for that key to be useful, I need to update it whenever I use my key on a new site/service. Dropping everything to go fetch my key is inconvenient, so I keep multiple…

I just have one in my drawer and one in my bag / always connected to my Mac

Then a printed backup sheets like 1password somewhere offsite (still needs master password to be usable)

Re: Google Fi seemingly affected by latest T-Mobile data breach

#35
post #15

Earlier quoted context omitted.

In the context of not trusting your ISP (the mobile provider in this case) a VPN provides a lot of security. You aren’t “adding an extra point of trust or potential failure”, you are choosing to trust your VPN provider instead of your ISP.

HTTPS already provides the same protection. VPN doesn't add anything for that. About the only meaningful feature VPN provides is presenting a different IP address to the server. VPN provides negligible extra security for most people, while adding extra exposure.

VPNs are significantly better wrt protection than HTTPS.

VPNs create a separation between the client and the server (as you mentioned) so not only can the server (or those eavesdropping on the server's connection) not see the client's IP, those eavesdropping on the client can't see what services they are connecting to (other than the VPN).

Of course by combining knowledge from multiple sources you can still build a fingerprint but VPNs with sufficient utilization can serve as a mixer to obfuscate which users are taking part in which traffic. Doubly so if the VPN supports multi-hop routing where the client side VPN and the server side VPN are at different sites.

Really as long as you aren't leaking DNS and you use a reasonably secure + well utilized VPN, your client should appear as a black box that shouts opaque contents at a single server without leaking many details about the actual communication taking place.

Compare this with HTTPS + no VPN where only the contents are obscured and everyone eavesdropping (aka the ISP or anyone on the same network) can see every service you are connected to. That alone should be enough to fingerprint a given connection to a specific user.

Re: Google Fi seemingly affected by latest T-Mobile data breach

#36

Earlier quoted context omitted.

I don't have a regular movement pattern and only activate the SIM when needed. I also rotate SIM's with my partner to confuse things more. We are part of a budding trend.

[flagged]

> You're paranoid-delusional, and engaging in cargo-cult spycraft where your education seems to be mostly centered around watching hollywood "lone wolf, former spy / contract killer trying to stay off the radar" type movies.

> you're nowhere near as interesting or important as you seem to think you are.

You actually had some decent points; are the aggressive personal attacks really necessary?

Or as the site guidelines put it,

> When disagreeing, please reply to the argument instead of calling names. "That is idiotic; 1 + 1 is 2, not 3" can be shortened to "1 + 1 is 2, not 3."

Re: Google Fi seemingly affected by latest T-Mobile data breach

#37
post #21
post #9

Earlier quoted context omitted.

Oof, that's not good. As a Fi user, I'm pretty angry at the moment even though I got the other version of the notice. That's because one of the main reasons I was using Fi in the first place was the perceived protection against sim swapping, via a super locked down special purpose Google account and the apparent inability of T-Mobile CSRs to access Fi customer data. The first thing I thought upon reading the notice w…

The why is obvious. People will lose their 2FA. It's a fact of life. Lost keys with your yubikey. Broken phone without a backup of your totp. Etc. After that, how do you prove that someone owns their account? Send a photocopy of your passport? No way to edit a picture, right? Answer some security questions, which you certainly forgot the answer to. And people are likely using the same questions with the same answer o…

Recently, Instagram asked to verify an account I have been using for past 2 year. Spent over $100 on ads.

I felt stupid and embarassed taking my own selfie with a piece of paper with a number written on it. But then I would have lost my account, had to do it.

Re: Google Fi seemingly affected by latest T-Mobile data breach

#38

Earlier quoted context omitted.

[flagged]

> You're paranoid-delusional, and engaging in cargo-cult spycraft where your education seems to be mostly centered around watching hollywood "lone wolf, former spy / contract killer trying to stay off the radar" type movies. > you're nowhere near as interesting or important as you seem to think you are. You actually had some decent points; are the aggressive personal attacks really necessary? Or as the site guideline…

Fine, I'll try to dial it back.

Also: telling someone they're not remotely as interesting as they think they are is not an insult, it's a factual statement that nobody who engages in the sort of tracking OP is worried about, would be interested in tracking the vast, vast vast majority of us. But since you're quoting the rule book, I'll qualify it.

Re: Google Fi seemingly affected by latest T-Mobile data breach

#39
post #15

Earlier quoted context omitted.

> only use it for data over a VPN Unless you run this yourself, I don't understand why you nor anyone thinks that adds to their data integrity? VPNs can, have, and are the subject of break-ins and have their own agenda and or government oversight. People think that VPNs are this magical black box that makes you secure and private, because the YouTube ads told everyone so, the reality is that you are just adding an ex…

In the context of not trusting your ISP (the mobile provider in this case) a VPN provides a lot of security. You aren’t “adding an extra point of trust or potential failure”, you are choosing to trust your VPN provider instead of your ISP.

[deleted]

Re: Google Fi seemingly affected by latest T-Mobile data breach

#40
post #15

Earlier quoted context omitted.

In the context of not trusting your ISP (the mobile provider in this case) a VPN provides a lot of security. You aren’t “adding an extra point of trust or potential failure”, you are choosing to trust your VPN provider instead of your ISP.

HTTPS already provides the same protection. VPN doesn't add anything for that. About the only meaningful feature VPN provides is presenting a different IP address to the server. VPN provides negligible extra security for most people, while adding extra exposure.

I assume there's a sizable segment of VPN users who enjoy torrenting without DMCA letters catching up with them, FWIW. HTTPS doesn't help much with that.
Post reply on HN