Live data from Hacker News

Even with 2FA, Google accounts can be hacked with just a phone number

ello.co

11–20 of 128 posts

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#11
post #3

This leaves so many open questions. Foremost: How did they guess his GMail password? Is there a way to access GMail without knowing the password? Ie. by sending a reset password per SMS?

They enabled call forwarding and got Google to call with a password reset code.

Its not clear how they got his phone number though.

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#13
Interesting, so adding 2FA actually decreased security... Well shit. Interesting case that shows just how unpredictable such things can be.

As far as I understand, though, 2FA increased the attack surface in this case. A web interface itself still remains impenetrable, doesn't it (know your hard-to-guess password and you should be fine)? Mobile provider was the weakest link and any system is as secure as its weakest link.

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#14

Interesting, so adding 2FA actually decreased security... Well shit. Interesting case that shows just how unpredictable such things can be. As far as I understand, though, 2FA increased the attack surface in this case. A web interface itself still remains impenetrable, doesn't it (know your hard-to-guess password and you should be fine)? Mobile provider was the weakest link and any system is as secure as its weakest…

It's similar to security questions in that way. If you answer them truthfully, then they can be used to attack you.

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#15
I work as a sales rep in-store for a telco. From a security perspective, it's ridiculous.

We use computer monitors which customers face from the same angle as us. I'm sure someone thought it would make the retail scenario more inclusive, but security-wise it's a mess. I can't verify account details without pulling up those same details for the customer to see. So I ask people for their details, click the button, and cross my fingers that they're right. If they're wrong, what then? They might legitimately not have known whose name it was under. It might be under their dad, mom, partner or business' name. Doesn't matter, the system has absolutely no design affordances to allow multiple people various levels of security privilege in accessing and altering accounts which are used by more than one person.

Furthermore, we have no organisational clarity about access privileges. Everyone makes up their own standards. Some people in the company are very strict, and won't do a SIM swap without photo ID or full ID over the phone. Some people will do one if the customer quotes the same last name and could be theoretically the account-holder's child. But does it matter when any customer can easily find out name, DOB and address from coming in store, then call up and get the SIM changed over the phone? We do have account PINs but very few people set them. And you could find it out in store if you were sharp-eyed.

There's a constant tension between providing a good customer experience and protecting security and privacy. But our commission is based partly on customer experience feedback scores - and if you're the one asshole who tries to follow all the rules (or follow what you decide should be the rules, because there aren't any haha) then you're gunna get a) bad feedback and b) alienate and make life difficult for the majority of ambiguous security events, which I'm sure are 95-99% trustworthy people.

Anyone relying on two-factor auth with a phone number who uses my company is vulnerable. Simple as that. It would take a determined attacker a day to get control of your number. All you'd notice was that your SIM stopped working. It would all be too late by the time you'd gotten a new one re-activated - and you're still vulnerable.

I'm not sure what telcos are like in other countries but I doubt much better.

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#17
post #6
post #5

Earlier quoted context omitted.

Thanks. I think I'll remove my phone number as a backup option.

Google periodically prompts me on login to add my cell phone number to increase my account's security. I think someone confused about what "increase" means. (And this is all the more surprising because in general I see all sorts of parts of Google making great end-user security decisions.)

It probably increases security for the average user, but decreases it for a targeted user.

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#18
post #16

Disable SMS for 2-step and SMS for password resets and use a 2-step mobile app. https://support.google.com/accounts/answer/1066447

After enabling 2FA, disabling SMS for 2-step and SMS for password resets, and ensuring that you don't have any phone number set as a way to get into you account, what is your plan for continuing to use your account if your phone is stolen?

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#19
post #2

Well I heard from a friend of mine that in Argentina the cellphone provider can access to your info. The case was this one. He was cheating her girlfriend, a friend of her accessed to my friend's text messages log, saw the evidence, and told to the gf about it. Apparently, but I never confirmed this, the friend (the one who read the messages) worked in the cellphone provider of my friend. Since then I know I can't tr…

Of course your cell phone provider can access your call logs. Probably even fairly low-level workers can get full access under certain conditions.

And of course some workers will abuse that access for personal reasons.

What did you expect? That workers at a phone company wouldn't be able to access your account info? Ideally, it would be compartmentalized, but...

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#20
post #16

Disable SMS for 2-step and SMS for password resets and use a 2-step mobile app. https://support.google.com/accounts/answer/1066447

After enabling 2FA, disabling SMS for 2-step and SMS for password resets, and ensuring that you don't have any phone number set as a way to get into you account, what is your plan for continuing to use your account if your phone is stolen?

Backup codes.
Post reply on HN