Earlier quoted context omitted.
Are you sure that's an attempted grammar nitpick? I thought they were saying the data lost clearly is non-negligible.
I suppose I'm not, but given the parent is flagged and dead, and I've got a handful of upmods...my interpretation was the same as many others. This highlights the importance of clear communication.
Google Fi seemingly affected by latest T-Mobile data breach
81–88 of 88 posts
Re: Google Fi seemingly affected by latest T-Mobile data breach
#82Earlier quoted context omitted.
I have used both. During that time I've lost access to SMS due to my phone breaking (twice), I have lost permanent access to online banking because the bank will not accept an international number. I came extremely close to losing access to my entire Google account because I use Fi and you need to sign into Google to activate it on your phone, but you need to be able to receive SMS to sign in to Google. Meanwhile, I…
> I have multiple yubikeys that are as hard to lose or break as a house key. Unfortunately, hard and easy are interchangeable in this sentence. And if you lose your house key you can always call a locksmith or just break a window to get inside. Even if you don’t have identification on you, if the cops show up you can have your neighbors vouch for you (assuming the cops don’t already personally know you).
Re: Google Fi seemingly affected by latest T-Mobile data breach
#83This could be a dumb question, and I assume the answer is no, but could the SIM serial data potentially be used to aid in a SIM spoof attack?
At least 1 reported case of a Fi customer being SIM swapped because of this breach.
Re: Google Fi seemingly affected by latest T-Mobile data breach
#84Earlier quoted context omitted.
The why is obvious. People will lose their 2FA. It's a fact of life. Lost keys with your yubikey. Broken phone without a backup of your totp. Etc. After that, how do you prove that someone owns their account? Send a photocopy of your passport? No way to edit a picture, right? Answer some security questions, which you certainly forgot the answer to. And people are likely using the same questions with the same answer o…
Recently, Instagram asked to verify an account I have been using for past 2 year. Spent over $100 on ads. I felt stupid and embarassed taking my own selfie with a piece of paper with a number written on it. But then I would have lost my account, had to do it.
I understand needing to verify the identity of people transferring large amounts of money, but it was a ridiculous ask for someone who just wanted it to send a friend 10 bucks for lunch. I just used another app, and my identity is still frozen in Venmo to this day. The silver lining is that no one can open an account with my information to circumvent the freeze, so I'm safe in that respect on Venmo.
Re: Google Fi seemingly affected by latest T-Mobile data breach
#85Not everyone got this version of the notice. Here's a reddit user who posted [1] that they were SIM swapped: > Additionally, on January 1, 2023 for about 1 hour 48 minutes, your mobile phone service was transferred from your SIM card to another SIM card. During the time of this temporary transfer, the unauthorized access could have involved the use of your phone number to send and receive phone calls and text message…
> could have involved the use of your phone number to send and receive phone calls Surely from their logs they know if these calls/texts happened? If, during that period no calls/sms's occurred, then there has been no breach - the attacker was close to their target, but walked away with nothing. If messages/calls were made, the user really needs to know who they were to/from to make any informed decisions. And Google…
Why would they have logs of calls/texts that weren't routed to them?
Re: Google Fi seemingly affected by latest T-Mobile data breach
#86Earlier quoted context omitted.
I don't have a regular movement pattern and only activate the SIM when needed. I also rotate SIM's with my partner to confuse things more. We are part of a budding trend.
[flagged]
https://news.ycombinator.com/newsguidelines.html
https://news.ycombinator.com/item?id=33292588 (Oct 2022)
https://news.ycombinator.com/item?id=32729960 (Sept 2022)
https://news.ycombinator.com/item?id=32729939 (Sept 2022)
https://news.ycombinator.com/item?id=31842940 (June 2022)
https://news.ycombinator.com/item?id=30436952 (Feb 2022)
Re: Google Fi seemingly affected by latest T-Mobile data breach
#87Earlier quoted context omitted.
> You're paranoid-delusional, and engaging in cargo-cult spycraft where your education seems to be mostly centered around watching hollywood "lone wolf, former spy / contract killer trying to stay off the radar" type movies. > you're nowhere near as interesting or important as you seem to think you are. You actually had some decent points; are the aggressive personal attacks really necessary? Or as the site guideline…
Fine, I'll try to dial it back. Also: telling someone they're not remotely as interesting as they think they are is not an insult, it's a factual statement that nobody who engages in the sort of tracking OP is worried about, would be interested in tracking the vast, vast vast majority of us. But since you're quoting the rule book, I'll qualify it.
p.s. I posted https://news.ycombinator.com/item?id=34606566 before seeing this subthread; I didn't mean to pile on. But yes, please dial it back. You've broken the site guidelines a great deal and I don't want to ban you.
Re: Google Fi seemingly affected by latest T-Mobile data breach
#88Earlier quoted context omitted.
Oof, that's not good. As a Fi user, I'm pretty angry at the moment even though I got the other version of the notice. That's because one of the main reasons I was using Fi in the first place was the perceived protection against sim swapping, via a super locked down special purpose Google account and the apparent inability of T-Mobile CSRs to access Fi customer data. The first thing I thought upon reading the notice w…
The why is obvious. People will lose their 2FA. It's a fact of life. Lost keys with your yubikey. Broken phone without a backup of your totp. Etc. After that, how do you prove that someone owns their account? Send a photocopy of your passport? No way to edit a picture, right? Answer some security questions, which you certainly forgot the answer to. And people are likely using the same questions with the same answer o…
The multi-day delay even sounds like a good idea, in case someone triggers that system with the intent to steal mail -- it gives the still-able-to-login real user time to veto it.
(If you want a level of anonymity, you can rent a PO box, use a commercial mail handling agent, register c/o a lawyer, etc.)