Live data from Hacker News

Google Fi seemingly affected by latest T-Mobile data breach

9to5google.com

71–80 of 88 posts

Re: Google Fi seemingly affected by latest T-Mobile data breach

#71
post #6

The same probably goes for other MVNO carriers such as Mint and Ting. The PII and billing data is with the MVNO carriers. I buy my SIM cards anonymously. I never use cellular near my house and only use it for data over a VPN. So it would not affect me if all of their data was breached.

> I buy my SIM cards anonymously. What's the methodology for doing this successfully?

Use cash to buy prepaid SIM card from someplace like Bustbuy.

Use virtual card from service such as privacy.com to add funds.

Never make calls or SMS with the SIM card number. Instead use VOIP such as jmp.chat or voip.ms.

Re: Google Fi seemingly affected by latest T-Mobile data breach

#72
post #6

The same probably goes for other MVNO carriers such as Mint and Ting. The PII and billing data is with the MVNO carriers. I buy my SIM cards anonymously. I never use cellular near my house and only use it for data over a VPN. So it would not affect me if all of their data was breached.

What threat model does this help with?

This is for anybody who does not want their call and SMS history, location history, or billing information leaked, breached, or sold to government or commercial entities.

Re: Google Fi seemingly affected by latest T-Mobile data breach

#73
post #22

Earlier quoted context omitted.

Oof. Trying to be a grammar pedant on the internet and getting it wrong. Big L there, homes.

Are you sure that's an attempted grammar nitpick? I thought they were saying the data lost clearly is non-negligible.

I suppose I'm not, but given the parent is flagged and dead, and I've got a handful of upmods...my interpretation was the same as many others.

This highlights the importance of clear communication.

Re: Google Fi seemingly affected by latest T-Mobile data breach

#74
post #62

Earlier quoted context omitted.

How are you handling multiple Yubikeys? I'm doing it personally and it's so annoying that I can't imagine recommending this to anyone else. Since I'd hate to lose access to everything if my house burns down, I keep a key outside of the home. Of course, for that key to be useful, I need to update it whenever I use my key on a new site/service. Dropping everything to go fetch my key is inconvenient, so I keep multiple…

Fireproof safe, and living in an area where the fire department would be able to get the fire under control fast enough that I would hopefully not need 1/10th of the capability of that safe. Edit: also, if your house burns down, won’t you probably have your keys on you if you’re not home?

I had a good fireproof safe burn once it fused the sand or whatever material is between the layers of metal. I was never able to get back into it.

Re: Google Fi seemingly affected by latest T-Mobile data breach

#75
post #2

A reasonable headline could state "Google Fi essentially not affected by latest T-Mobile data breach". Look at the data "breached": > limited data including when your account was activated, data about your mobile service plan, SIM card serial number, and active or inactive account status. > It does not contain your name, date of birth, email address, payment card information, social security number or tax IDs, driver…

SIM swaps were reported, so this is definitely a breach that impacts Google Fi customers.

Re: Google Fi seemingly affected by latest T-Mobile data breach

#76
post #3

This could be a dumb question, and I assume the answer is no, but could the SIM serial data potentially be used to aid in a SIM spoof attack?

At least 1 reported case of a Fi customer being SIM swapped because of this breach.

Re: Google Fi seemingly affected by latest T-Mobile data breach

#78
post #62

Earlier quoted context omitted.

How are you handling multiple Yubikeys? I'm doing it personally and it's so annoying that I can't imagine recommending this to anyone else. Since I'd hate to lose access to everything if my house burns down, I keep a key outside of the home. Of course, for that key to be useful, I need to update it whenever I use my key on a new site/service. Dropping everything to go fetch my key is inconvenient, so I keep multiple…

Fireproof safe, and living in an area where the fire department would be able to get the fire under control fast enough that I would hopefully not need 1/10th of the capability of that safe. Edit: also, if your house burns down, won’t you probably have your keys on you if you’re not home?

Although these keys are intended to be stored on a keychain, I don't know of anyone that actually uses them that way. If you work remotely, there's just no need to have your keys on you most of the time. One of my keys is a 5C Nano and it just sits in the laptop all day long. So, if my house burns, I'm losing any keys in the house along with it.

As for a fireproof safe, I do have one, but they're rated for X hours and degrade over time. I should probably get a new one.

Re: Google Fi seemingly affected by latest T-Mobile data breach

#79

Earlier quoted context omitted.

How are you handling multiple Yubikeys? I'm doing it personally and it's so annoying that I can't imagine recommending this to anyone else. Since I'd hate to lose access to everything if my house burns down, I keep a key outside of the home. Of course, for that key to be useful, I need to update it whenever I use my key on a new site/service. Dropping everything to go fetch my key is inconvenient, so I keep multiple…

I use Windows hello and Apple passkey as secondary fido devices, isn’t that a valid method??

Maybe? I really don't know. I dual-boot a Linux & Windows workstation and have a macOS laptop, so I haven't looked too deeply into platform-specific solutions. For now, I stick with Yubikeys. Complicating things further is for some accounts I'd like to give my wife access and she has her own keys and own devices. I've hit the key registration limit on some sites.

Re: Google Fi seemingly affected by latest T-Mobile data breach

#80
post #27
post #21

Earlier quoted context omitted.

The why is obvious. People will lose their 2FA. It's a fact of life. Lost keys with your yubikey. Broken phone without a backup of your totp. Etc. After that, how do you prove that someone owns their account? Send a photocopy of your passport? No way to edit a picture, right? Answer some security questions, which you certainly forgot the answer to. And people are likely using the same questions with the same answer o…

I have used both. During that time I've lost access to SMS due to my phone breaking (twice), I have lost permanent access to online banking because the bank will not accept an international number. I came extremely close to losing access to my entire Google account because I use Fi and you need to sign into Google to activate it on your phone, but you need to be able to receive SMS to sign in to Google. Meanwhile, I…

Yeah I've got enough yubikeys that I'm very unlikely to lose them all. The only thing that I'm vulnerable to right now is a house-burns-down kind of situation, and I'm considering storing a yubikey at someone else's house to get offsite backup.
Post reply on HN