this post was submitted on 17 Jan 2024
54 points (100.0% liked)
Asklemmy
43944 readers
597 users here now
A loosely moderated place to ask open-ended questions
Search asklemmy ๐
If your post meets the following criteria, it's welcome here!
- Open-ended question
- Not offensive: at this point, we do not have the bandwidth to moderate overtly political discussions. Assume best intent and be excellent to each other.
- Not regarding using or support for Lemmy: context, see the list of support communities and tools for finding communities below
- Not ad nauseam inducing: please make sure it is a question that would be new to most members
- An actual topic of discussion
Looking for support?
Looking for a community?
- Lemmyverse: community search
- sub.rehab: maps old subreddits to fediverse options, marks official as such
- !lemmy411@lemmy.ca: a community for finding communities
~Icon~ ~by~ ~@Double_A@discuss.tchncs.de~
founded 5 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Difficult to tell what happened without knowing the full context.
It has happened that scammers call support, say they're XYZ and lost their 2fa device. 2fa gets disabled and they can overtake the account in some old fashioned way.
Also there is SIM splitting and other techniques. Also the youtuber could be wrong. These attacks are very subtle until it's too late.
Give us a link (with timestamp if it's long), maybe someone can find out more. [Edit: Thx for the link.]
Damn I assumed google customer reps couldn't do that without verifying. How do you even protect from that? Besides not using one account for everything
Edit: I assumed porting out scam too but what confuses me about it was that his carrier line was still actively recieveing SMS and my understanding is that after a port out, the old sim becomes invalid/not working.
Sure, customer reps shouldn't help with account recovery unless they get proper verification. I'm sure many companies have learned from past mistakes. I think that's the only way to solve it. I'm not sure though if this is what has happened here... These crypto people seem to have hacked many accounts last year.
Maybe related video from Linus Tech Tips incident last march: https://piped.video/watch?v=yGXaAWbzl5A
Adam Koralik talks a bit fast and some details aren't clear to me. For example if he got recovery mails and sms from his own actions or if this was the scammer. Also I'm not sure how 2fa works with YouTube. I certainly hope changing the account password makes it ask for the second factor or it's next to useless. If this is the case he must have gotten phished or there is another unknown security issue in the process. Or his password didn't get changed in the first place. But that also can't be it since he clearly tells he got the notification mails for a password change and changed recovery methods.
Concerning your edit: I've read that, too. That your connection drops, once a new SIM card gets activated. That might take a while, though, or not happen with some carriers or under certain circumstances. As far as i know a cell network is a crazy mix of technology. And from his description it's not even clear to me when he talks about SMS and when he talks about notification emails or push notifications.
And in other youtubers' videos I've heard they usually seperate their accounts so that it's not the same account for private stuff on their phone and the important youtube stuff all mixed in the same account.