SIM swap horror story: I've lost decades of data and Google won't lift a finger

Discussion in 'other security issues & news' started by ZMsiXone, Jun 17, 2019.

  1. ZMsiXone

    ZMsiXone Registered Member

    Joined:
    Mar 30, 2017
    Posts:
    326
    Location:
    EUROPE/poland/germany
  2. mirimir

    mirimir Registered Member

    Joined:
    Oct 1, 2011
    Posts:
    9,252
  3. imdb

    imdb Registered Member

    Joined:
    Nov 2, 2011
    Posts:
    4,208
    good grief, what a nightmare. :eek: i guess it goes to show that there's not much you can do to stop a dedicated hacker.
     
  4. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    But I wonder how this SIM swapping problem can be solved? Because nowadays most websites offer 2FA combined with SMS.
     
  5. mirimir

    mirimir Registered Member

    Joined:
    Oct 1, 2011
    Posts:
    9,252
    On some sites, users must provide GnuPG public keys. Sometimes even login requires signing, and then submitting, a challenge string.

    Basically, that's how Bitcoin etc transactions are authenticated. So perhaps that could be packaged in a more user-friendly way for site authentication.

    But then, there's no recourse if you lose the private key. And that's the tradeoff, I guess. As long as you have a safety net for lost credentials, you have a vulnerability for account theft. And of course, if someone steals the private key, you're screwed.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.