SIM swap horror story: I've lost decades of data and Google won't help
zdnet.com
zdnet.com
It's a situation that is mind-boggling. Users as asked to place a significant chunk of their digital lives in the care of Google, it is unbelievable that they fail this badly. It's useful to note than it's not a situation that business users face. People who pay for G-suite have real support, even ::gasp:: telephone support. Why on earth does google not offer this to consumer users? I would gladly pay for that level of support and security. For that matter if there were some way of converting my personal account over to G-Suite I would do so.
I would even not mind something like one-time payments for support calls, for example pay $50 for a service call to get assistance in a case like this. I just can't fathom the "no support" model at all.
I know people are getting sick of this phrase, but I'm going to repeat it here anyway because it answers your question perfectly: why doesn't Google have customer support? They do, but if the product is free, you're not the customer.
As you note, Google does have real customer support for people who pay. The other people are not customers, they are advertising targets. Why waste money on support for them?
The concern I'd have with G-One is that if you lost access to your account, you also aren't a Google One customer, and the support likely won't assist you. Creating a chicken/egg situation.
On the other hand, a paid edge case support option for otherwise free services would be a win for both sides. If only the long term projection of the resulting incentives would not be so ugly...
I switched to iCloud which supports the download feature.
Phone -> Dropbox + Google Photos (automatically)
Card-based cameras -> Plug in card, Dropbox + Google Photos pick up new photos
Backup 'server': Local synced Dropbox folder -> Local + Cloud backups
I couldn't see how to add iCloud to my existing syncs / backups. When I looked at it, I couldn't be sure it would keep photos on my phone long enough to allow Dropbox and Google Photos to pick them up. It's good that it's possible to get the originals over at a MacOS machine. Might be worth exploring then.
HN discussion: https://news.ycombinator.com/item?id=20166131
I can just see the people raging about this on social media now.
“Google charged me $50 to fix an issue with my account!”
“Google won’t give me any help unless I pay them! Extortion artists!”
Etc.
For a fee, you get marked as a high-risk/high-value account, get the recovery service and risky factors of authentication get extra scrutiny, etc.
https://mobile.twitter.com/patio11/status/114040469625693798...
- Don't allow upgrading after a problem arises to get premium support: "Google won't let me pay to fix my account"
- Allow upgrading after a problem arises to get premium support: "Google extorting me to regain access to my account"
EDIT: actually it looks like the support might need to be reached from within the account, so that's still a major problem when you can't get in at all.
One of Google One’s selling points Google advertises is phone based access to Google experts.
https://support.apple.com/en-us/HT204921 "If you need more help, contact Apple Support. While we can answer your questions about the account recovery process, we can't verify your identity or expedite the process in any way."
Have you considered alternatives that do offer support?
I can think of paid services that compete in the domains google operates in. Fastmail is an easy one.
It seems like one of the most important lessons of computer security has already been forgotten: It's only as good as the weakest link. Not only this but decentralization/redundancy is often better than centralization/dependency. For example, I'm not sitting awake at night worrying over some semi-pseudo password I generated for an old unencrypted forum run on some random persons server.
I had something very similar happen when I got a new number. I kept getting calls for the previous owner from what I assume to have been a bank, a library (for passed-due books no less; left a voice mail), and random people trying to contact this person. Not long thereafter, I started getting text updates from Facebook any time one of their contacts posted something. Facebook fortunately disables this with the text message STOP (IIRC) [1], but it bothered me that a nefarious actor could have passively collected the names of this person's contacts, messages, or more.
Not quite sure what to do, I did end up calling most of them back to inform them they had the wrong number, if they left a voice mail. The calls stopped about a year and a half later, and while I was somewhat annoyed at the time, in retrospect it could have been much worse!
One caveat: I'm not certain that it's identical to what Takeout provides. I downloaded the mbox file via Takeout and the Takeout version was a fair bit larger than my Thunderbird mbox file as I recall. Maybe Thunderbird stores the emails more efficiently than Takeout? I should examine this more closely. As far as I am aware there are no missing emails in Thunderbird, though I could write a script to be certain.
Edit: Seems that I misremembered. The Takeout file seems to be appreciably smaller than what Thunderbird has, but in line with what Gmail reports at the bottom. I guess Thunderbird is actually less efficient than Gmail. Attachments might explain some of this, as I deleted some attachments in Gmail that I kept in Thunderbird.
There's a new checkbox in takeout that lets you schedule a backup every 2 months (and then presumably you'll get an email when you need to download it).
Does anyone else have issues with takeout failing with "unknown error occurred" if you use the default of selecting all products? I have to manually create multiple takeout archives (one for gmail, one for photos, one for location history...)
> With access to your XXX@YYY.ZZZ Box account, Google Download Your Data can:
> Read and write all files and folders stored in Box
Nope. Download link it is.
The API scope doesn't have any knowledge of individual files or applications. https://developer.box.com/docs/scopes
Conversely, Google Drive does have scopes available for Application specific folder read/write https://developers.google.com/drive/api/v3/appdata
So box needs to up its game.
https://landing.google.com/advancedprotection/
(The usual disclosure: I work for Google, but not on anything related to this, only speaking as a user.)
The thing is, not long ago I had no issue recovering my account if it got compromised. I think attackers today have gotten better at finding ways to beat the system. One thing I’ve seen, albeit I don’t know if it works on Google accounts, is enabling high security after stealing an account, effectively making recovery very hard.
Though, I can’t really speculate on if that’s what’s going on here.
No opinion on SMS specifically but there are tradeoffs.
Or in more detail, the credentials aren't human readable and are per-FQDN, so when you visit badguy.example thinking it's goodguy.example, your Security Key will cheerfully hand over valid credentials for badguy.example, but there is no way to give them credentials for goodguy.example because that's not where you are.
Hence that 100% score on Google's page.
Believe it or not banks are really bad at security. They are so bad at it that they don't even realize how bad at it they are. But the banks all copy from each other so "what the other guy is doing" is more or less their justification for what they do. Most of them have little to no idea why they do what they do for IT security, they just do what the Computer Security for Dummies book says to do (walk through the IT security department at any big bank and I bet you there is a dog eared copy of that tome on every desk)
Synchrony is one of the worst offenders, they won't even let you change your password without doing SMS verification, and their source of phone numbers is a Transunion skip trace database (which you can't change or remove any information from), so getting past Synchrony can be as easy as filling out a contest form at a mall, waiting for the phone number to appear with Transunion, then choosing that phone number to do SMS verification. It might take a couple months but payoff can be huge.
My hero at the moment is Capital One, they allow you to do e-mail authentication instead of SMS, and their iOS app also doubles as an additional factor (one requiring you to enter your password or use touch ID to use).
I was also extremely happy to find that the brokerage Robinhood offers Google Auth as a second factor. E*Trade also offers 2FA but a proprietary token w/ lcd display (which they happily charge you for).
My trick has been to give banks a false phone number that rings busy forever. That does effectively keep me from using banks that require SMS authentication, but there are more then enough that either offer other methods or drop their SMS requirement if you list your mobile number as your home number (indicating that its a wired phone and can't receive SMS). That doesn't keep my Synchrony accounts secure but there are enough protections around credit cards that my liability would be $50 at worst, with Synchrony having to eat the remainder of the loss.
I don't remember that ever being the case, either when Google first launched Google Authenticator and 2FA (when I pretty soon after set it up) or when I later went through the setup process for my work account at my current job (a couple years ago).
> We found that an SMS code sent to a recovery phone number helped block 100% of automated bots, 96% of bulk phishing attacks, and 76% of targeted attacks.
* https://security.googleblog.com/2019/05/new-research-how-eff...
Not everyone has to worry about being targeted by nation states.
Does it really disable all API access? I thought it only blocked certain OAuth scopes, but to be honest I haven’t really tried.
I was able to login to a NVIDIA Shield, but only by resetting and bootstrapping off a spare Android device (!!!) because U2F keys are broken on Shield. Interestingly, my Samsung TV remains signed into Youtube, which is kind of odd now that I think about it.
With that done, GitHub prompts me for my key. My Linux office workstation is missing the necessary udev rule, so I couldn't test more. (Funnily, pressing Cancel caused them to send me a SMS, so their 2FA is practically worthless).
This is how Github worked for me - I think it's just a mis-match in the code checking for U2F functionality...
Find an email provider that provides decent support, i.e. you can call and talk to a real person. Make sure they support 2FA (ideally the non SIM variant). Also recovery tokens that you can write down and stuff like that.
Personally I run my own mail server but I understand that's not everybody's cup of tea.
source: I work at fastmail. It's cool.
I am mostly just suggesting that folks who read stories like these and fear similar predicaments take the time, effort, expense, etc. to properly secure whatever accounts they have.
Thought experiment: if someone steals an account with no 2FA, enables U2F and other security mechanisms, how will support verify who truly owns the account? Or the reverse: user enables U2F and someone calls in and tries to claim the account was stolen?
Having humans make judgements is important because the real world is complicated and people are imperfect, but using U2F in the first place can save you a huge headache, no matter what services you use. If support can just flip a bit and disable U2F, it isn’t very useful for the same reasons accounts get hijacked to begin with.
And those things? It comes down to having strong process rules and having intelligent life forms make the decision.
And if not then why not? Is it because Google is a bigger and more obvious target or something specific they are doing badly?
If you think people should switch then these are the kind of questions you should answer.
This would happen with any email provider.
So the fix isn't changing email provider, it's using a more secure second factor, e.g. U2F.
https://security.googleblog.com/2019/06/use-your-android-pho...
I hope Apple some day supports NFC or maybe even USB U2F, both things Android has supported on phones for a bit.
https://techsolidarity.org/resources/security_key_gmail.htm
For no particular reason, Google does require you to temporarily configure phone-number based recovery while configuring other 2FA options -- but once they're set up, you don't need the phone number anymore.
Which is legitimately a pain in the ass to register, manage, keep in sync, etc but I only use it for a few very important accounts--Google being one of them.
I'm far more concerned with an attacker from the internet or destruction from a fire or natural disaster than someone using my computer at my home who happens to have my username/password combination as well.
1) Call your cellphone carrier and ask to set up a password/PIN to be used for when you call into the customer service phone number.
2) Consider your phone number and SIM card insecure. The phone carriers are ignoring the SIM swap problem even though they know how much damage it's causing. Give your phone number to as few companies as possible. Phone services such as Google Voice work without a SIM card, so they are less prone to problems. Give out such a phone number if necessary.
3) Don't use text message verification codes as 2FA. Use an authentication app, such as Google Authenticator.
4) You can retake possession of your hacked Gmail account by providing one of the previously used passwords. No need to have a working phone.
5) Ask yourself, what will happen if you lose both your laptop and your phone at once? Do you have things set up in a way where you can get back into your digital life? Someone can break into your home while you're away, the government can confiscate them at the airport, etc.
6) Check what email addresses you have configured as backup auth methods for your Gmail. Those accounts can be used as a means of access by a hacker.
That's possible?! I only ever change password if I suspect it might have been compromised. Now if a service allows to use old passwords, that's quite a bummer and makes password change meaningless.
Note that, at least for TMobile, AT&T, and Verizon, the password/PIN is presented to the CSR in plaintext (as they verify the pin over the phone verbally).
I'd assumed they'd transfer to some pin-capture applet to verify, but nope.
> Use an authentication app, such as Google Authenticator
If you decide on Google Authenticator, make sure you scan the barcode with 2 devices (say, your tablet and your phone) to back up that credential. Or just use Authy.
You can print out a copy of the barcode and keep it somewhere safe. It's a little bit scary as that barcode is a super powerful extra key but, you will have a key that will work and not be reliant on any device to store it.
What is really infuriating is that it is not required for BestBuy-type authorized resellers that hook directly into the system.
This is what I'm worried about, if I don't have a phone number on a gmail account, won't it make it harder to get access to that gmail account if I am locked out. Even though there's obviously a bad security loophole with just having a phone number on your account as a recovery option, is it not worse to be locked out of your account with no way to get in?
Yes! For example, if you're robbed on your way home from work, and they take your laptop and your mobile.
Your phone number is an obvious attack vector. I think having a dual sim phone with 2fa dedicated number that is not publicly associated with you, possibly with the carrier that has it's security in order, would decrease the odds of getting hacked.
My solution going forward will be to spend all of my money each month so there's nothing to steal, and have a terrible reputation online that therefore can't be ruined.
Way ahead of you there buddy
(sorry, I know, no jokes..)
While it doesn't automatically sync across devices, it does allow you to create backups[2] which can be encrypted with AES or your PGP key. Just store this in Dropbox/Drive/Box and offline storage and you're good to go.
[1] https://github.com/andOTP/andOTP/blob/master/README.md [2] https://raw.githubusercontent.com/flocke/andOTP/master/asset...
* all emergency/account recovery info changed
* Person contacts shortly thereafter claiming account hack
I lost a legacy skype account recently. It had had no email attached to it, so the hacker was able to add theirs and get notified whenever I got back into the account. There was no way to remove their email or add new security mechanisms without waiting 24 hours, so I had no way to keep them from resetting the password.
The account was shut down for spam not long after. As far as I could tell there was no way to effectively reach microsoft about this, despite being a paying office 365 customer. They had a security chat but it was a deadend, and slow.
Unfortunately, most sites do not allow you to turn off SMS recovery even if they offer other 2FA options.
Security is only as strong as the weakest link, and SMS is very weak.
Overall the situation isn’t great.
You can save the QR code that was used during setup to repeat the onboarding at any time. You can also use Authy, 1Password, or another service that lets you store the one-time password somewhere else. Or use U2F devices when possible.
It was a pain for all of them, but it was worst for the ones that I had no other auth systems set up. (Or the ones that had my old phone number for SMS still, even though I thought I'd changed it everywhere.)
In the end, there's still no good system for real security. You're either stuck with a device you might lose (or someone might steal), or stuck with an account that you might cancel (or someone might steal). Or use biometrics which are just not ready for prime time.
When you’re at Google scale, all of these methods have real world flaws.
So the likelihood of moving to a new phone without those codes transferred is very high. Not exactly an easy experience.
P.S. I might have a different perspective as where i am from, there really aren't important services (banks etc.) that are using sms 2FA. Mobile operators doesn't ship SIM cards over mail, you can get a new SIM only in person providing ID (or PIN/PUK in case of prepaid cards). Probably my country is just too small market for these kind of attacks so i feel secure enough when using sms 2FA.
1) he didn't use a password app
2) he thought google drive was a safe place for his stuff
3) he thought google drive was a secure place for his stuff
All three things, which I would bet are fairly common assumptions (the last 2 are certainly part of Google's marketing!), turned out to bite him.
https://gizmodo.com/a-tv-anchor-tries-to-gift-bitcoin-on-air...
It seems like this only happens to people who have poor opsec about their email addresses, phone numbers, and are publicly related to the cryptocurrency movement. I mean, I'm sure it happens to other people, but that's the only case I've ever heard about.
I would personally be wary about publicly listing the email I use with my bank, or my phone number, and I've done what I can to scrub the internet of these values. If you have to be publicly reachable through a medium other than Facebook or Twitter, have a separate email and phone number through which you conduct your serious personal business. But most people do not need this kind of public reachability, or else have it through work. For those types of people, it would behoove them to keep their profile small.
As for how hackers can swap someone's SIM, consider:
- Does the 20 year old minimum wage employee working at that store know how to spot a good quality fake ID card?
- What about hackers bribing an employee?
The problem is SMS account recovery, which is a really bad idea.
The problem is that a lot of services tie the two together. Often one implies the other. Even if it doesn't, though, it's also easier to social engineer -- "look! I have access to the 2fa phone number! I just can't access my password manager!"
What about hackers bribing an employee?
And then the change only happens after you confirm a text message sent to your phone asking you to approve the request.
But that doesn't contradict the point of the comment you were replying to, does it?
Edit: You should reply instead of just downvoting.
As with every generalizations, there are exceptions, but they generally only prove the rule.
Customer service has more to do with company-specific culture than what you actually paid. There are good and bad examples in every industry (or even with the same company).
They have enough local, physical presence so that I could show up in person and prove who I am. Also the personnel is already familiar with checking the identity and hopefully less suspectiple to social engineering.
2FA tokens and codesheets without SMS backup are secure, but bit tricky to manage. Takes some effort to distribute to different, secure places (think if house burns) and some regular checks to verify backup tokens are alive and codesheets not lost.
They can reach out and cause things to happen at a distance, but I don't want that used to authenticate me. They used it when I had lost my cards, to cause me to receive a bundle of cash so I could get on with my day just paying cash everywhere.
I have a specialized OTP device with a chiclet keyboard, and a password used for normal stuff. When I do something serious, like the time I bought somewhere to live, I call them to set up the transaction, then a different random person gets assigned to call me back and verify the details - this way if one employee goes rogue they can't empty my account by claiming I called them. They have a password for me, and the second employee uses that password so that I know it's really the bank calling me.
What bank is it? How did you find it?
I've not heard of features similar to this, especially the last part about buying a house.
It's a Telephone Bank in the UK, launched in 1989 and I became a customer a year or three after that. Because it doesn't have any branches its call centre staff have to be trained to handle absolutely anything - if they can't fix it then it won't get fixed.
I found it because my father used it, I have no idea why, he was not ordinarily a man to favour technologically sophisticated solutions, he never owned his own email address for example. Maybe as a working man he found it frustrating that other banks were closed after hours? First Direct is never closed, it operates 24/7. I have used other banks for some things, but I've always kept accounts with First Direct because of their truly extraordinary customer service hence I call it the "good bank". I actually know one of their Founders and apparently that commitment to customer service was key to their original vision for the bank, he led a strategy session for the start-up where I work now and it used that vision to give us a worked example. He was Chairman at another start-up I've worked for too. Small world.
For the buying a home part I do mean that I bought it outright by the way, there wasn't a mortgage or anything like that - so that's a lot of money, let's say six figures. I presume the precaution was triggered by the fact that I wanted to move this large sum (almost all the money I had) to an account I'd never sent any money to before. Sounds almost exactly like a scam.
I would _like_ to believe any other bank would have similar protections - but of course I don't buy a home every day, so I have no other examples to compare, and most of my contemporaries have a mortgage so the very large sums aren't involved.
The password when they call me thing was nice, to be honest they didn't proactively set that up. I suggested it off-handedly one day and they were like "Of course, yes, we can set that up". I presume it's not custom, just they didn't explicitly advertise it to me as an option. That happens a lot, I didn't want contactless on my new card recently, and they were like "Yup, of course, done. Replacements for this card will also not have contactless until you call to change that".
This might seem impractical for people who live somewhere that the provider doesn't have an office, but it actually isn't. There is a nationwide, readily available mechanism already in place for this. They are called notary publics.
It could work like this:
1. You request account recovery, and pay the fee, and provide your physical contact information.
2. The provider hires a notary public in your area, and sends them a form for you to sign authorizing the account recovery.
3. The notary meets with you, verifies your identity, notarizes your signature on the form, and then lets your provider know that this has successfully completed.
4. Now that the provider knows the request was legitimate, the recovery or transfer can go through.
Someone trusts faceless uncaring tech companies with all of their most crucial data.
Companies get hacked. User's life is crashed. Companies feel nothing and have pathetic "support".
"Thankfully", insider access grants privileges.
> Thankfully, I have a good friend at $COMPANY who was very concerned with my plight and was able to get $PRIVILEGED_SUPPORT
My point is that we have set up these systems that have us all skating on thin ice, and when people inevitable fall through (or are pulled under by thieves) we have almost no recourse, unless we happen to be well-connected to the internal workings of these machines.
We're turning the world into Morlocks and Eloi. We've got to wake up and slow this shit down.
These two snippets inspired /facepalm:
> While Twitter is a free service, I would still expect some level of assistance for someone who has had the same account for 13 years and can get thousands of people to verify my identity.
'free service' being the operative words, and they can probably trust the user to do all the hard work of maintaining a new account for another 13 years (with associated pageviews) without lifting a finger.
> I made sure to have two-factor authentication (2FA) enabled with this service. It turns out that the 2FA with text messaging sent to a cell phone may be useless when hackers steal your SIM right out from under you.
O RLY. The point of 2FA is that one of those factors is a physical token which cannot be stolen remotely. Anything involving SMS to a phone number is not 2FA and never will be 2FA and anyone claiming otherwise is either an idiot or assumes you are...
> After a couple of days, our bank reversed the $25,000 charge and told us that the fraud department caught the ACH withdrawal before it was fully processed so that neither my family nor the bank lost this money forever.
Mobile phone numbers shouldn't be used as a second factor, much less as a way to fully recover online credentials to your bank account.
There is the concept of "security VS convenience", a trade-off you make when using secured assets. 2FA is convenience just as much as it is security. By having SMS as a method to reset a password, you reduce the attackers workload from cracking a difficult password to "compromise your mobile phone physically or electronically". I trust my passphrases much more than my mobile device and/or carrier.
I guess the author learned that lesson, but… please don't. Backups in the cloud are fine, but such sensitive information has to be encrypted. Ideally with a 6 words diceware password or so.
And if it is meant for your close ones to recover if you die, write that password down, and lock it up in a couple homes you trust.
See: https://support.google.com/accounts/answer/7539956?hl=en
The insistence on using Chrome is arbitrary and I don't like it. The use of U2F rather than WebAuthn at least has a technical justification (older Android devices can't do WebAuthn, and while it's backward compatible in the sense that you can use a WebAuthn authentication having signed up with U2F, vice versa is not possible, so old Android devices would have a confusing UX behaviour) but the insistence on Chrome is just arbitrary lock-in.
I won't be dying on that hill either, but it does suck.
Supposedly this limitation is because Firefox doesn't implement the JavaScript calls that permit a U2F-calling site to know the type of U2F key being used and Google wants to enforce, when enrolling for ATP, that at least one of the two keys being enrolled can be used wirelessly (Bluetooth or NFC).
I don't agree with it either but will only truly be mad if/when Mozilla implements the requisite call and Google still blocks enrollment without Chrome.
What error did you see?
Of course I didn't notice until I came home. The dud card he gave me worked for 24 hours (I still don't understand how). And even after it stopped working, it took me quite some time to piece together everything that happened — I didn't realize that the SIM card I had wasn't mine for quite some time. Fortunately they did the equivalent of an identity theft smash-and-grab. It was relatively easy to identify and reverse, and they didn't compromise any tech 2FA services.
Interestingly Heathrow police didn't care as the "theft" was only a $5 SIM card and not a "high enough value item" to warrant investigation.
tldr: Don't let anyone ever touch your SIM cards.
What about the part that's "being a part of a criminal conspiracy to steal $40k?" I guess that's not something for the airport police to deal with though.
In light of the extended Fraud on your account, I believe
that due to the 7 day lapse between you collecting the SIM
and returning to the USA, then your details could have been
compromised anywhere. In all probability, this occurred in
the USA as this is where the accounts have been set up and
believed the fraudsters would have had to have been in order
to benefit from the crime.
The fact that you bought a SIM card in the UK is purely
circumstantial I’m afraid, therefore we would not
investigate this further.
Of course I was shouting "THEY HAD TO SHIP IT BACK TO THE U.S. FOR IT TO WORK" as well as providing the call logs documenting calls from the Atlanta region (where I don't live and hadn't visited), but it fell on deaf ears and I gave up. That response made me feel like a tin-hatted conspiracy theorist, though: yes, I am certain I was defrauded through an international criminal conspiracy.What you're telling us is all based on your educated guesses as to how they might have pulled this. There are things that feel a bit weird and I'm guessing you have no evidence to prove them, such as the scammer shipping the real SIM back to Atlanta in time before you realise the issue.
How did you realise the SIM card you were handed was fake? Couldn't it be that they instead duplicated your SIM whilst you weren't looking?
IMHO the police (or FBI or whatevs) in the US should conduct the investigation as that's were the fraud happened. They'll evaluate if it's worth it contacting their counterparts in the UK to move forward. However I also think it is good that you've given a heads up to the UK local authorities.
Do you remember what company was offering the local SIMs? I've seen mostly Lebara, but not in Heathrow...
I did also report it to both my local police and the FTC and the FBI but never could gain traction as nobody thought it was their jurisdiction. I eventually gave up once my credit was repaired.
I mean, what possible additional evidence could one plausibly have that the guessed scam is indeed what happened?
Which is the scary thing about all these SIM-theft things. It clear happened, there's really no way for the victim to know how/where/what/when/who.
I do wonder if it's still happening...
I think one way to prevent it, aside from remembering to not let your SIM off your hands is to mark/paint your SIM and make it unique and easily recognizable.
Then you can deal with it immediatelly, even if you forget the rule to not give your SIM temporarily to others. (You'll probaly not forget, but people who may not have your experience and still want to protect themselves against this, may.) Also the attackers will not probably attempt to swap unique looking SIM in the first place.
that being said it's just plain silly how important these crummy devices are, and how little information and warnings they come with.
set a good sim pin, that will save u from this type of trouble. of course, it won't save u from physical phone / sim access.
Edit: Thanks for correcting me- I guess my SIM does not have a PIN.
I pay for Drive (now part of Google One) and they advertise free phone support with it. I've never used it, and it turns out it's not a phone number you can call, but rather you request a call from them:
https://support.google.com/googleone/contact/googleone_c2c?h...
So there is a level of support for paying customers... at least in theory. I haven't heard of anyone's experiences with it in practice, however.
Curious if anyone here has tried Google One support, and whether their reps have the ability to escalate issues, the way G Suite reps can?
One of the things I do is periodically spool off ephemeral data to BD-R's (write once Blu-Ray disks). At 25GB a pop they aren't super dense but I don't actually generate more 'new' data than that in a given month. It was something I do because when I started in this business I made backups because crappy disk drives would lose data. But these days you can get crypto ransomed and poof all that data unavailable?
There is no doubt a market for some new 'best practices' for data security. Perhaps No Starch Press will get someone to collect those ideas into a book.
The most annoying part about this is that Twitter demands your phone number. You can't use another method for 2FA, such as U2F or OTP. I assume it's not at all because they want to authorize you or keep your account safe, but rather because they want to be able to identify you. User's lose both privacy and security.
Just to clarify, you can use U2F to login, but you can’t only use U2F. Eventually you’ll be locked out of your account (after logging in) and forced to provide a valid number.
Are you sure?
* https://www.yubico.com/works-with-yubikey/catalog/twitter/
If he's really talking about the SIM PIN, I don't think having one helps against this kind of attack. The SIM PIN is to prevent people in possession of your physical SIM from using your cellular account for voice or data.
What you need with T-Mobile is a separate PIN that is required for porting out your number [1]. You set this PIN up by calling support.
https://support.t-mobile.com/docs/DOC-37477
Note that it can be set up via the T-Mobile web site, alternative to the phone support line.Perhaps it would be interesting to get a few pre-paid SIM cards and see if it there is any Google accounts connected to them?
The issue is partially that while social engineering countermeasures that could help prevent sim swaps could be helped by better training and more rigorous security checks, there are actually bad actors who are employees of the carriers who can be paid off to switch SIMs.
I'm pretty sure 611 works without a SIM card.
For a non-carrier-branded device though, perhaps the presence of a SIM card is required.
I just had my AT&T sim swapped two weeks ago. According to police, the sim swappers are insiders at the telcos or have compromised corporate credentials and are logging into the telco admin portal and processing the swaps themselves.
I’ve now switched to Google Fi. I’m banking on the assumption that Google doesn’t keep an admin portal open to the internet and that they don’t give sim swap/port access to employees that aren’t paid well enough to be willing to take a small bribe to swap the sims.
This is why you should never store passwords on your computer / cloud in plain text.
> Given that I had 2FA enabled for my bank account and the bank account info on Google Drive, it was just a matter of time before the thief started stealing my money.
Is it common in the United States to allow online banking without any physical second factor? My bank requires me to use some kind of device similar to https://en.wikipedia.org/wiki/Chip_Authentication_Program with my card and code to login or execute transactions. I think most other banks in my country require something similar.
* Twitter requires you to enable cell-phone based 2nd factor before they let you enable any other 2nd factor. Luckily in my case their buggy software determined that my cell phone number is "incorrect", so I was never able to.
* Twilio (the authors of Authy!) let you use TOTP codes from Authy in addition to SMS-based 2FA. There is no way to disable the SMS authentication, so your account is never secure.
* Many banks assume that SMS is a secure channel, which it isn't, and force its use as 2FA.
This should get more publicity and companies should be called out on forcing people to use SMS as a 2nd factor. There are many reasons why this is a bad idea, and the story described in the article is just one of many possible attacks.
1Password is also guilty of this in a different way: They won't let you register a U2F physical security key unless you also have a virtual security key on the account.
This is ridiculously simple. I'll spell it out:
1) Offer Virtual, U2F, and SMS-based multi-factor authentication. SMS is still useful for convenience on platforms which pose less of a security risk to your digital life.
2) Don't gatekeep methods of multi-factor authentication behind others.
3) Allow multiple devices for each method of multi-factor authentication, especially physical U2F keys.
4) Offer backup codes.
5) Offer an Enhanced Lockdown option, whereby customer support account recovery is irrevocably impossible in the event of lost multi-factor.
I'll… just leave this here without any further comment.
You are not their customer. You are their product.
This is quite literally true. They only have to care for us cattle enough to keep us as good products.
I have all this in my gmail also, but my mail downloads to my computer (I use Mail on my Mac). My Mail application data in turn backs up to a few backup drives, so I have this data in several places.
Do people use gmail without having a copy stored anywhere else? I totally get that this guy has been screwed many different ways, including by Google, but it seems unwise to not have a backup copy of your mail anywhere.
The amount of indifference to suffering by people in the corporate world today has gotten...I am not even sure what the word is.
> Through all of these hacks, it was interesting to find that Facebook was the one reliable and secure service under my control.
Perhaps their comment was attempting to provide some anecdotal data in an effort to explain why the author's Facebook account remained secure.
Though I agree with you in the sense that it's far more likely that they simply commented on the wrong article. :)
I have a really odd, obscure problem with SMB and Windows 10 and would really like to just call up a Microsoft tech support hotline like they used to have, except they don't even offer a paid service for that any more to consumers. Got a problem with Windows? Get fucked!
In the past, I did use a verizon landline phone number as Verizon had the ability to "lock/freeze" that number from any outside changes, but I got rid of my landline a while ago.
Also, print out some backup codes and stick it in your wallet.
I have no idea what month and year I created my google account, and google doesn't seem to make that info available to you in a simple manner.
The idea of backup codes is good. Putting them in your wallet reduces your security though. Depending on the value of your accounts, you give a (physical) attacker everything he or she needs to compromise you.
If you are going to keep these things on your person, consider protecting them with a hand-written cipher. Example: https://www.schneier.com/academic/solitaire/
I know of one approach that might get results, but he's already done it: publicly shame them in an article. It's the only way to get results from these algorithm-driven companies that lack anything resembling an actual customer service department.
https://support.google.com/chrome/answer/165139?visit_id=636...
It pays to be skeptical with your data. 3 copies. 2 local one offsite. If your only copy is offsite in the control of someone else... that's a terrible decision.
Anyone have experience with this, or heard reports of attacks by means of forged physical ID?
"T-Mobile suggests adding its port validation feature to all accounts. To do this, call 611 from your T-Mobile phone or dial 1-800-937-8997 from any phone. The T-Mobile customer care representative will ask you to create a 6-to-15-digit passcode that will be added to your account."
While there is apparently a desktop interface, if someone gets access to my phone, they have the live access codes right there. When the SIM is stolen, can the authenticator also be accessed with the new location of that identity?
The process for moving Authenticator involves receiving a six digit Google code on your phone -- which was just effectively stolen with the SIM...
While Google may have built in protections, they are not obvious at this point to me, a casual user of Google Authenticor.
Does anyone have any more information to keep this more secure?
Also note that there is no official desktop client, anything that claims to be is 3rd party and wouldn't be connected to your current codes.
[0]: https://myaccount.google.com/signinoptions/two-step-verifica...
My solution to all of it is literally just 2 emails. Both 2fa. Recovery exists but the numbers and emails are unknown to the world beyond Google or m$ servers. And those don't get used to register anything ever. I park my recoveries then use my main email as my most public one. Everything else is registered and recoverable on the second email that also isn't publicly known unless one of the services I'm attached to gets their data leaked etc etc etc....so even if they did successfully swap my SIM they can't get anything else.
TMobile got hacked a few months back and around the same time my personal debit card that stayed in my wallet the whole time and I don't ever use in public literally for that reason. Got charged. They tried to empty it all. I pressed and pressed the only thing they could do for me was ask for a specific code. Verbal 2fa. I think if I remember correctly none of the data showed up publicly anywhere yet not sure about the specific incident I just thought the timing was weird.
If that's the best security TMobile has and that's all their customer support has to offer us. They have failed as a company in my eyes. And it will only get worse not better as more middle managers get their cut of the security upgrades that they will partially and incorrectly implement.
Of course they won't lift a finger your not a Kardashian