The problem is SMS account recovery, which is a really bad idea.
The problem is that a lot of services tie the two together. Often one implies the other. Even if it doesn't, though, it's also easier to social engineer -- "look! I have access to the 2fa phone number! I just can't access my password manager!"
And then the change only happens after you confirm a text message sent to your phone asking you to approve the request.
What about hackers bribing an employee?
P.S. I might have a different perspective as where i am from, there really aren't important services (banks etc.) that are using sms 2FA. Mobile operators doesn't ship SIM cards over mail, you can get a new SIM only in person providing ID (or PIN/PUK in case of prepaid cards). Probably my country is just too small market for these kind of attacks so i feel secure enough when using sms 2FA.
1) he didn't use a password app
2) he thought google drive was a safe place for his stuff
3) he thought google drive was a secure place for his stuff
All three things, which I would bet are fairly common assumptions (the last 2 are certainly part of Google's marketing!), turned out to bite him.
https://gizmodo.com/a-tv-anchor-tries-to-gift-bitcoin-on-air...
It seems like this only happens to people who have poor opsec about their email addresses, phone numbers, and are publicly related to the cryptocurrency movement. I mean, I'm sure it happens to other people, but that's the only case I've ever heard about.
I would personally be wary about publicly listing the email I use with my bank, or my phone number, and I've done what I can to scrub the internet of these values. If you have to be publicly reachable through a medium other than Facebook or Twitter, have a separate email and phone number through which you conduct your serious personal business. But most people do not need this kind of public reachability, or else have it through work. For those types of people, it would behoove them to keep their profile small.
As for how hackers can swap someone's SIM, consider:
- Does the 20 year old minimum wage employee working at that store know how to spot a good quality fake ID card?
- What about hackers bribing an employee?