Viewing profile — davidscoville
davidscoville
HN member- Joined
- Wed, Aug 16, 2017, 4:27 PM UTC
- HN karma
- 180
- Public activity
- 12 items
- HN profile
- View on Hacker News ↗
About davidscoville
No profile information was provided.
Recent public activity
-
comment
Comment #49160159
I’d like to know about algorithms that determine where elevators “rest” during downtime. In the morning maybe all rest on the ground floor. Then perhaps during midday lunch rush, s…
-
comment
Comment #45270061
Yes, at least two emails. One was the spoofed email from legal@google.com (which sadly convinced me this was legit) and the other was a Google recovery code email. The spoofed emai…
-
comment
Comment #45268933
I did have saved passwords in Chrome password manager but they were old. My guess is that the attacker used Google SSO on Coinbase (e.g., "sign in with Google"), which I have used …
-
comment
Comment #45268873
That's the big question. I've heard attackers have used Google's own tools like Google forms or Google cloud to send the email through Google's servers so it wasn't flagged. This i…
-
comment
Comment #45268850
I updated the post and include the headers & html of the bounced-copy, although I don't think it's very useful.
-
comment
Comment #45268464
I think the attacker had my password, and they just needed a recovery method, which was the code I read over the phone. I have no idea how they had my password, I never share passw…
-
comment
Comment #45268441
I lost the original email—the attacker deleted all evidence and then cleared my trash (and yes I tried using the Google tool to find deleted emails, but the attacker cleared that t…
-
comment
Comment #45267727
The code I read to them was a Google account recovery code. That’s how they accessed my Google account. I, mistakenly, believed they needed to confirm I was still alive and the rig…
-
comment
Comment #45266167
Exactly. Google created vulnerabilities for the whole industry by introducing cloud synced Authenticator codes.
-
comment
Comment #45265713
I’ve heard scammers use Google tools like Google forms or Google cloud to send out fraudulent emails that appear like they come from Google.
-
comment
Comment #45265698
I believe they logged into coinbase with Google SSO. And then they used my Google Authenticator codes which were cloud synced as the second factor auth method. A warning to auth en…
- story