Not everyone got this version of the notice. Here's a reddit user who posted [1] that they were SIM swapped: > Additionally, on January 1, 2023 for about 1 hour 48 minutes, your mobile phone service was transferred from your SIM card to another SIM card. During the time of this temporary transfer, the unauthorized access could have involved the use of your phone number to send and receive phone calls and text message…
Oof, that's not good. As a Fi user, I'm pretty angry at the moment even though I got the other version of the notice. That's because one of the main reasons I was using Fi in the first place was the perceived protection against sim swapping, via a super locked down special purpose Google account and the apparent inability of T-Mobile CSRs to access Fi customer data. The first thing I thought upon reading the notice w…
Google Fi seemingly affected by latest T-Mobile data breach
51–60 of 88 posts
Re: Google Fi seemingly affected by latest T-Mobile data breach
#52Earlier quoted context omitted.
The why is obvious. People will lose their 2FA. It's a fact of life. Lost keys with your yubikey. Broken phone without a backup of your totp. Etc. After that, how do you prove that someone owns their account? Send a photocopy of your passport? No way to edit a picture, right? Answer some security questions, which you certainly forgot the answer to. And people are likely using the same questions with the same answer o…
The solution is a government issued key pair. Probably on a Yubikey type of device. Replacing a lost one of those is then the same process as replacing a lost driver's license / passport / other government issued identification. By 2023 it's high time for these forms of identification to catch up with the digital age. It's high time to end the joke of verifying identity by birthday, SSN, "in-security questions", and…
Re: Google Fi seemingly affected by latest T-Mobile data breach
#53Re: Google Fi seemingly affected by latest T-Mobile data breach
#54Re: Google Fi seemingly affected by latest T-Mobile data breach
#55Earlier quoted context omitted.
Oof, that's not good. As a Fi user, I'm pretty angry at the moment even though I got the other version of the notice. That's because one of the main reasons I was using Fi in the first place was the perceived protection against sim swapping, via a super locked down special purpose Google account and the apparent inability of T-Mobile CSRs to access Fi customer data. The first thing I thought upon reading the notice w…
The why is obvious. People will lose their 2FA. It's a fact of life. Lost keys with your yubikey. Broken phone without a backup of your totp. Etc. After that, how do you prove that someone owns their account? Send a photocopy of your passport? No way to edit a picture, right? Answer some security questions, which you certainly forgot the answer to. And people are likely using the same questions with the same answer o…
In comparison SMS works the same for all services - its an easy choice.
Re: Google Fi seemingly affected by latest T-Mobile data breach
#56Earlier quoted context omitted.
The why is obvious. People will lose their 2FA. It's a fact of life. Lost keys with your yubikey. Broken phone without a backup of your totp. Etc. After that, how do you prove that someone owns their account? Send a photocopy of your passport? No way to edit a picture, right? Answer some security questions, which you certainly forgot the answer to. And people are likely using the same questions with the same answer o…
I have used both. During that time I've lost access to SMS due to my phone breaking (twice), I have lost permanent access to online banking because the bank will not accept an international number. I came extremely close to losing access to my entire Google account because I use Fi and you need to sign into Google to activate it on your phone, but you need to be able to receive SMS to sign in to Google. Meanwhile, I…
Unfortunately, hard and easy are interchangeable in this sentence. And if you lose your house key you can always call a locksmith or just break a window to get inside.
Even if you don’t have identification on you, if the cops show up you can have your neighbors vouch for you (assuming the cops don’t already personally know you).
Re: Google Fi seemingly affected by latest T-Mobile data breach
#57Re: Google Fi seemingly affected by latest T-Mobile data breach
#58Earlier quoted context omitted.
The why is obvious. People will lose their 2FA. It's a fact of life. Lost keys with your yubikey. Broken phone without a backup of your totp. Etc. After that, how do you prove that someone owns their account? Send a photocopy of your passport? No way to edit a picture, right? Answer some security questions, which you certainly forgot the answer to. And people are likely using the same questions with the same answer o…
In Germany there is a process called PostIdent by Deutsche Post. Any business can send you a QR code which you take to the local post office and a teller will verify your ID. The business is being notified next to instantly and you can proceed with whatever is needed. It's a nice and smooth process. Businesses could also use the German government ID, which has a chip with cryptography functionality built in.
Re: Google Fi seemingly affected by latest T-Mobile data breach
#59Earlier quoted context omitted.
Solution is multiple yubikeys or printing out backup codes.
How are you handling multiple Yubikeys? I'm doing it personally and it's so annoying that I can't imagine recommending this to anyone else. Since I'd hate to lose access to everything if my house burns down, I keep a key outside of the home. Of course, for that key to be useful, I need to update it whenever I use my key on a new site/service. Dropping everything to go fetch my key is inconvenient, so I keep multiple…
Unless you need the GnuPG or SSH applets, I just use the $14 FIDO keys from Identiv. They are also NFC capable for my mobile devices also. I keep one at my office, one at home and carry one in my pack.
I too wish there were a way to keep them in sync or back them up.
Maybe a virtual FIDO key? https://github.com/bulwarkid/virtual-fido
Re: Google Fi seemingly affected by latest T-Mobile data breach
#60A reasonable headline could state "Google Fi essentially not affected by latest T-Mobile data breach". Look at the data "breached": > limited data including when your account was activated, data about your mobile service plan, SIM card serial number, and active or inactive account status. > It does not contain your name, date of birth, email address, payment card information, social security number or tax IDs, driver…
I mean the fact is that Google Fi gave my information to a third party that suffered from a breach, which leaked some amount of data. I’m happy it’s not that much data, personally, but it’s still a breach. And from other comments in the thread it seems like some were affected more than that.
>system is used for Google Fi customer support purposes and contains limited data including when your account was activated, data about your mobile service plan, SIM card serial number, and active or inactive account status.
>It does not contain your name, date of birth, email address, payment card information, social security number or tax IDs, driver’s license or other form of government ID, or financial account information, passwords or PINs that you may use for Google Fi, or the contents of any SMS messages or calls.