Live data from Hacker News

Google Fi seemingly affected by latest T-Mobile data breach

9to5google.com

41–50 of 88 posts

Re: Google Fi seemingly affected by latest T-Mobile data breach

#41
post #21

Earlier quoted context omitted.

The why is obvious. People will lose their 2FA. It's a fact of life. Lost keys with your yubikey. Broken phone without a backup of your totp. Etc. After that, how do you prove that someone owns their account? Send a photocopy of your passport? No way to edit a picture, right? Answer some security questions, which you certainly forgot the answer to. And people are likely using the same questions with the same answer o…

Recently, Instagram asked to verify an account I have been using for past 2 year. Spent over $100 on ads. I felt stupid and embarassed taking my own selfie with a piece of paper with a number written on it. But then I would have lost my account, had to do it.

i used to use linkedin from a different location from my current one. i didn't think about this but when i tried to log in from my present location, it said something bullshit about "security" and now i am forced to upload my passport for verification and they pinky promise to delete the photo after verification. no fucking way

Re: Google Fi seemingly affected by latest T-Mobile data breach

#42
post #26

Earlier quoted context omitted.

Solution is multiple yubikeys or printing out backup codes.

How are you handling multiple Yubikeys? I'm doing it personally and it's so annoying that I can't imagine recommending this to anyone else. Since I'd hate to lose access to everything if my house burns down, I keep a key outside of the home. Of course, for that key to be useful, I need to update it whenever I use my key on a new site/service. Dropping everything to go fetch my key is inconvenient, so I keep multiple…

I use Windows hello and Apple passkey as secondary fido devices, isn’t that a valid method??

Re: Google Fi seemingly affected by latest T-Mobile data breach

#43
post #6

The same probably goes for other MVNO carriers such as Mint and Ting. The PII and billing data is with the MVNO carriers. I buy my SIM cards anonymously. I never use cellular near my house and only use it for data over a VPN. So it would not affect me if all of their data was breached.

> I buy my SIM cards anonymously.

What's the methodology for doing this successfully?

Re: Google Fi seemingly affected by latest T-Mobile data breach

#44
post #26

Earlier quoted context omitted.

Solution is multiple yubikeys or printing out backup codes.

How are you handling multiple Yubikeys? I'm doing it personally and it's so annoying that I can't imagine recommending this to anyone else. Since I'd hate to lose access to everything if my house burns down, I keep a key outside of the home. Of course, for that key to be useful, I need to update it whenever I use my key on a new site/service. Dropping everything to go fetch my key is inconvenient, so I keep multiple…

This has been what stops me from going full webauthn, instead right now I use 3 yubikeys with pass (password store) and encrypt with 3 separate gpg keys (one private key stored on each yubikey), I haven't touched one of the yubikeys in a year but I know that if I lose the other two it can still decrypt my passwords.

The disadvantage here is obviously it's just another password manager instead of taking full advantage of hardware tokens, but I want to be able to enroll passwords or tokens without the key present all the time. (Also, yubikeys have limited slots for keys)

Re: Google Fi seemingly affected by latest T-Mobile data breach

#45
post #2

A reasonable headline could state "Google Fi essentially not affected by latest T-Mobile data breach". Look at the data "breached": > limited data including when your account was activated, data about your mobile service plan, SIM card serial number, and active or inactive account status. > It does not contain your name, date of birth, email address, payment card information, social security number or tax IDs, driver…

I mean the fact is that Google Fi gave my information to a third party that suffered from a breach, which leaked some amount of data. I’m happy it’s not that much data, personally, but it’s still a breach. And from other comments in the thread it seems like some were affected more than that.

Re: Google Fi seemingly affected by latest T-Mobile data breach

#47
post #26
post #21

Earlier quoted context omitted.

The why is obvious. People will lose their 2FA. It's a fact of life. Lost keys with your yubikey. Broken phone without a backup of your totp. Etc. After that, how do you prove that someone owns their account? Send a photocopy of your passport? No way to edit a picture, right? Answer some security questions, which you certainly forgot the answer to. And people are likely using the same questions with the same answer o…

Solution is multiple yubikeys or printing out backup codes.

The one time I had to use backup codes with Google they simply didn't work. Fortunately I was still logged on at my home comptuer.

Re: Google Fi seemingly affected by latest T-Mobile data breach

#48
post #21
post #9

Earlier quoted context omitted.

Oof, that's not good. As a Fi user, I'm pretty angry at the moment even though I got the other version of the notice. That's because one of the main reasons I was using Fi in the first place was the perceived protection against sim swapping, via a super locked down special purpose Google account and the apparent inability of T-Mobile CSRs to access Fi customer data. The first thing I thought upon reading the notice w…

The why is obvious. People will lose their 2FA. It's a fact of life. Lost keys with your yubikey. Broken phone without a backup of your totp. Etc. After that, how do you prove that someone owns their account? Send a photocopy of your passport? No way to edit a picture, right? Answer some security questions, which you certainly forgot the answer to. And people are likely using the same questions with the same answer o…

The solution is a government issued key pair. Probably on a Yubikey type of device. Replacing a lost one of those is then the same process as replacing a lost driver's license / passport / other government issued identification.

By 2023 it's high time for these forms of identification to catch up with the digital age. It's high time to end the joke of verifying identity by birthday, SSN, "in-security questions", and other easily leaked information. And obviously 2FA by SMS is not good either.

Re: Google Fi seemingly affected by latest T-Mobile data breach

#49
post #21
post #9

Earlier quoted context omitted.

Oof, that's not good. As a Fi user, I'm pretty angry at the moment even though I got the other version of the notice. That's because one of the main reasons I was using Fi in the first place was the perceived protection against sim swapping, via a super locked down special purpose Google account and the apparent inability of T-Mobile CSRs to access Fi customer data. The first thing I thought upon reading the notice w…

The why is obvious. People will lose their 2FA. It's a fact of life. Lost keys with your yubikey. Broken phone without a backup of your totp. Etc. After that, how do you prove that someone owns their account? Send a photocopy of your passport? No way to edit a picture, right? Answer some security questions, which you certainly forgot the answer to. And people are likely using the same questions with the same answer o…

In Germany there is a process called PostIdent by Deutsche Post. Any business can send you a QR code which you take to the local post office and a teller will verify your ID. The business is being notified next to instantly and you can proceed with whatever is needed.

It's a nice and smooth process.

Businesses could also use the German government ID, which has a chip with cryptography functionality built in.

Re: Google Fi seemingly affected by latest T-Mobile data breach

#50
post #21

Earlier quoted context omitted.

The why is obvious. People will lose their 2FA. It's a fact of life. Lost keys with your yubikey. Broken phone without a backup of your totp. Etc. After that, how do you prove that someone owns their account? Send a photocopy of your passport? No way to edit a picture, right? Answer some security questions, which you certainly forgot the answer to. And people are likely using the same questions with the same answer o…

The solution is a government issued key pair. Probably on a Yubikey type of device. Replacing a lost one of those is then the same process as replacing a lost driver's license / passport / other government issued identification. By 2023 it's high time for these forms of identification to catch up with the digital age. It's high time to end the joke of verifying identity by birthday, SSN, "in-security questions", and…

I think Estonia started doing this like 20 years ago. [1]

[1] https://e-estonia.com/solutions/e-identity/id-card/

Post reply on HN