Live data from Hacker News

Alleged leak of more than 5M Gmail accounts

isleaked.com

61–70 of 141 posts

Re: Alleged leak of more than 5M Gmail accounts

#61
post #32

Now is a good time to enable two-factor authentication on your accounts. Here is how to do so for some common services: - Google: https://www.google.com/landing/2step/ - Github: https://github.com/settings/security - AWS: http://aws.amazon.com/mfa/virtual_mfa_applications - Facebook: https://www.facebook.com/settings?tab=security - Twitter: https://twitter.com/settings/security - Dropbox: https://www.dropbox.com/acco…

With two-factor authentication you are happily providing gmail with your phone number. They say they need this to send you a verification code when you log into your gmail account. Then they say: "During sign-in, you can tell us not to ask for a code again on that particular computer." Well, if that's the trick, they don't need your phone nr at all, they can do ip and os check anyways..

If you're worried about giving Google your phone number, you should perhaps also be worried about them having access to all of your email messages.

Re: Alleged leak of more than 5M Gmail accounts

#62
post #2

Every time something like this is posted, where there is a site to check if your email address is in some leaked list, I really wish they'd just tell me how to get the list itself. Instead, they ask me to trust that they will not use my email address, and I have to hope that they won't leak it. I generally don't bother, because it's just more security risks.

It could be even more dangerous than you are imagining. If you check a username, then you would probably also be revealing the IP address range and browser referrer that is normally used to access your account. Google uses IP address and location to help detect illegal access. So giving away this information could make it easier for your account to be stolen.

How? Is the hacker going to buy a plane ticket, fly to my home and plug his laptop into my network?

Re: Alleged leak of more than 5M Gmail accounts

#65
post #32

Now is a good time to enable two-factor authentication on your accounts. Here is how to do so for some common services: - Google: https://www.google.com/landing/2step/ - Github: https://github.com/settings/security - AWS: http://aws.amazon.com/mfa/virtual_mfa_applications - Facebook: https://www.facebook.com/settings?tab=security - Twitter: https://twitter.com/settings/security - Dropbox: https://www.dropbox.com/acco…

With two-factor authentication you are happily providing gmail with your phone number. They say they need this to send you a verification code when you log into your gmail account. Then they say: "During sign-in, you can tell us not to ask for a code again on that particular computer." Well, if that's the trick, they don't need your phone nr at all, they can do ip and os check anyways..

My gmail(and aws and dropbox and digital ocean and github and zoho and ...) TFA uses a TOTP app, not my phone number. (and works just fine on my iPad - which doesn't really have a phone number - at least not one I know or worry about...)

Also, according to the three biggest telcos where I live:

"SMS is not designed to be a secure communications channel and should not be used by banks for electronic funds transfer authentication," ( http://www.itnews.com.au/News/322194,telcos-declare-sms-unsa... )

Re: Alleged leak of more than 5M Gmail accounts

#66
post #51

Earlier quoted context omitted.

With two-factor authentication you are happily providing gmail with your phone number. They say they need this to send you a verification code when you log into your gmail account. Then they say: "During sign-in, you can tell us not to ask for a code again on that particular computer." Well, if that's the trick, they don't need your phone nr at all, they can do ip and os check anyways..

I'm not sure exactly what point you're trying to make, but you seem confused about how 2FA works. The goal of 2FA/MFA is to make you demonstrate that you're in possession of two independent secrets (authentication factors). Once you've shown that, it's considered safe enough to replace the second secret (OTP sent to your phone or generated by your TOTP app like Google Authenticator) with a cookie (the check is not IP…

> If what you're concerned about is the idea that Google knows your phone number, you can use Google Authenticator or another TOTP app instead.

I'm under the impression that you need to provide Google your phone number before being allowed to enable TOTP.

Re: Alleged leak of more than 5M Gmail accounts

#67
post #62

Earlier quoted context omitted.

It could be even more dangerous than you are imagining. If you check a username, then you would probably also be revealing the IP address range and browser referrer that is normally used to access your account. Google uses IP address and location to help detect illegal access. So giving away this information could make it easier for your account to be stolen.

How? Is the hacker going to buy a plane ticket, fly to my home and plug his laptop into my network?

Of course not. He's going to go botnet shopping and try to log in through a compromised machine with an IP address in the same town, in the same address range.

He might even be able to use the same IP as you, if you happen to be using a gateway with many machines behind it, and one of them is compromised.

Re: Alleged leak of more than 5M Gmail accounts

#68
post #32

Now is a good time to enable two-factor authentication on your accounts. Here is how to do so for some common services: - Google: https://www.google.com/landing/2step/ - Github: https://github.com/settings/security - AWS: http://aws.amazon.com/mfa/virtual_mfa_applications - Facebook: https://www.facebook.com/settings?tab=security - Twitter: https://twitter.com/settings/security - Dropbox: https://www.dropbox.com/acco…

I don't want 2FA for absolutely everything. I want to authenticate once.

Re: Alleged leak of more than 5M Gmail accounts

#69
post #32

Now is a good time to enable two-factor authentication on your accounts. Here is how to do so for some common services: - Google: https://www.google.com/landing/2step/ - Github: https://github.com/settings/security - AWS: http://aws.amazon.com/mfa/virtual_mfa_applications - Facebook: https://www.facebook.com/settings?tab=security - Twitter: https://twitter.com/settings/security - Dropbox: https://www.dropbox.com/acco…

With two-factor authentication you are happily providing gmail with your phone number. They say they need this to send you a verification code when you log into your gmail account. Then they say: "During sign-in, you can tell us not to ask for a code again on that particular computer." Well, if that's the trick, they don't need your phone nr at all, they can do ip and os check anyways..

> Well, if that's the trick, they don't need your phone nr at all, they can do ip and os check anyways.

Although that wouldn't be 2FA, it's worth noting that Facebook, Hotmail and Flickr will ask for some extra verification if you connect from a different country that usual. So that's probably not a bad idea.

Post reply on HN