Earlier quoted context omitted.
The why is obvious. People will lose their 2FA. It's a fact of life. Lost keys with your yubikey. Broken phone without a backup of your totp. Etc. After that, how do you prove that someone owns their account? Send a photocopy of your passport? No way to edit a picture, right? Answer some security questions, which you certainly forgot the answer to. And people are likely using the same questions with the same answer o…
Recently, Instagram asked to verify an account I have been using for past 2 year. Spent over $100 on ads. I felt stupid and embarassed taking my own selfie with a piece of paper with a number written on it. But then I would have lost my account, had to do it.
Google Fi seemingly affected by latest T-Mobile data breach
41–50 of 88 posts
Re: Google Fi seemingly affected by latest T-Mobile data breach
#42Earlier quoted context omitted.
Solution is multiple yubikeys or printing out backup codes.
How are you handling multiple Yubikeys? I'm doing it personally and it's so annoying that I can't imagine recommending this to anyone else. Since I'd hate to lose access to everything if my house burns down, I keep a key outside of the home. Of course, for that key to be useful, I need to update it whenever I use my key on a new site/service. Dropping everything to go fetch my key is inconvenient, so I keep multiple…
Re: Google Fi seemingly affected by latest T-Mobile data breach
#43The same probably goes for other MVNO carriers such as Mint and Ting. The PII and billing data is with the MVNO carriers. I buy my SIM cards anonymously. I never use cellular near my house and only use it for data over a VPN. So it would not affect me if all of their data was breached.
What's the methodology for doing this successfully?
Re: Google Fi seemingly affected by latest T-Mobile data breach
#44Earlier quoted context omitted.
Solution is multiple yubikeys or printing out backup codes.
How are you handling multiple Yubikeys? I'm doing it personally and it's so annoying that I can't imagine recommending this to anyone else. Since I'd hate to lose access to everything if my house burns down, I keep a key outside of the home. Of course, for that key to be useful, I need to update it whenever I use my key on a new site/service. Dropping everything to go fetch my key is inconvenient, so I keep multiple…
The disadvantage here is obviously it's just another password manager instead of taking full advantage of hardware tokens, but I want to be able to enroll passwords or tokens without the key present all the time. (Also, yubikeys have limited slots for keys)
Re: Google Fi seemingly affected by latest T-Mobile data breach
#45A reasonable headline could state "Google Fi essentially not affected by latest T-Mobile data breach". Look at the data "breached": > limited data including when your account was activated, data about your mobile service plan, SIM card serial number, and active or inactive account status. > It does not contain your name, date of birth, email address, payment card information, social security number or tax IDs, driver…
Re: Google Fi seemingly affected by latest T-Mobile data breach
#46Re: Google Fi seemingly affected by latest T-Mobile data breach
#47Earlier quoted context omitted.
The why is obvious. People will lose their 2FA. It's a fact of life. Lost keys with your yubikey. Broken phone without a backup of your totp. Etc. After that, how do you prove that someone owns their account? Send a photocopy of your passport? No way to edit a picture, right? Answer some security questions, which you certainly forgot the answer to. And people are likely using the same questions with the same answer o…
Solution is multiple yubikeys or printing out backup codes.
Re: Google Fi seemingly affected by latest T-Mobile data breach
#48Earlier quoted context omitted.
Oof, that's not good. As a Fi user, I'm pretty angry at the moment even though I got the other version of the notice. That's because one of the main reasons I was using Fi in the first place was the perceived protection against sim swapping, via a super locked down special purpose Google account and the apparent inability of T-Mobile CSRs to access Fi customer data. The first thing I thought upon reading the notice w…
The why is obvious. People will lose their 2FA. It's a fact of life. Lost keys with your yubikey. Broken phone without a backup of your totp. Etc. After that, how do you prove that someone owns their account? Send a photocopy of your passport? No way to edit a picture, right? Answer some security questions, which you certainly forgot the answer to. And people are likely using the same questions with the same answer o…
By 2023 it's high time for these forms of identification to catch up with the digital age. It's high time to end the joke of verifying identity by birthday, SSN, "in-security questions", and other easily leaked information. And obviously 2FA by SMS is not good either.
Re: Google Fi seemingly affected by latest T-Mobile data breach
#49Earlier quoted context omitted.
Oof, that's not good. As a Fi user, I'm pretty angry at the moment even though I got the other version of the notice. That's because one of the main reasons I was using Fi in the first place was the perceived protection against sim swapping, via a super locked down special purpose Google account and the apparent inability of T-Mobile CSRs to access Fi customer data. The first thing I thought upon reading the notice w…
The why is obvious. People will lose their 2FA. It's a fact of life. Lost keys with your yubikey. Broken phone without a backup of your totp. Etc. After that, how do you prove that someone owns their account? Send a photocopy of your passport? No way to edit a picture, right? Answer some security questions, which you certainly forgot the answer to. And people are likely using the same questions with the same answer o…
It's a nice and smooth process.
Businesses could also use the German government ID, which has a chip with cryptography functionality built in.
Re: Google Fi seemingly affected by latest T-Mobile data breach
#50Earlier quoted context omitted.
The why is obvious. People will lose their 2FA. It's a fact of life. Lost keys with your yubikey. Broken phone without a backup of your totp. Etc. After that, how do you prove that someone owns their account? Send a photocopy of your passport? No way to edit a picture, right? Answer some security questions, which you certainly forgot the answer to. And people are likely using the same questions with the same answer o…
The solution is a government issued key pair. Probably on a Yubikey type of device. Replacing a lost one of those is then the same process as replacing a lost driver's license / passport / other government issued identification. By 2023 it's high time for these forms of identification to catch up with the digital age. It's high time to end the joke of verifying identity by birthday, SSN, "in-security questions", and…