Live data from Hacker News

Viewing profile — davidscoville

davidscoville

HN member
Joined
Wed, Aug 16, 2017, 4:27 PM UTC
HN karma
180
Public activity
12 items

About davidscoville

No profile information was provided.

Recent public activity

  1. comment
    Comment #49160159

    I’d like to know about algorithms that determine where elevators “rest” during downtime. In the morning maybe all rest on the ground floor. Then perhaps during midday lunch rush, s…

  2. comment
    Comment #45270061

    Yes, at least two emails. One was the spoofed email from legal@google.com (which sadly convinced me this was legit) and the other was a Google recovery code email. The spoofed emai…

  3. comment
    Comment #45268933

    I did have saved passwords in Chrome password manager but they were old. My guess is that the attacker used Google SSO on Coinbase (e.g., "sign in with Google"), which I have used …

  4. comment
    Comment #45268873

    That's the big question. I've heard attackers have used Google's own tools like Google forms or Google cloud to send the email through Google's servers so it wasn't flagged. This i…

  5. comment
    Comment #45268850

    I updated the post and include the headers & html of the bounced-copy, although I don't think it's very useful.

  6. comment
    Comment #45268464

    I think the attacker had my password, and they just needed a recovery method, which was the code I read over the phone. I have no idea how they had my password, I never share passw…

  7. comment
    Comment #45268441

    I lost the original email—the attacker deleted all evidence and then cleared my trash (and yes I tried using the Google tool to find deleted emails, but the attacker cleared that t…

  8. comment
    Comment #45267727

    The code I read to them was a Google account recovery code. That’s how they accessed my Google account. I, mistakenly, believed they needed to confirm I was still alive and the rig…

  9. comment
    Comment #45266167

    Exactly. Google created vulnerabilities for the whole industry by introducing cloud synced Authenticator codes.

  10. comment
    Comment #45265713

    I’ve heard scammers use Google tools like Google forms or Google cloud to send out fraudulent emails that appear like they come from Google.

  11. comment
    Comment #45265698

    I believe they logged into coinbase with Google SSO. And then they used my Google Authenticator codes which were cloud synced as the second factor auth method. A warning to auth en…

  12. story