What strikes me most in these stories, is how you always have to find some higher ranking company employee through personal connections in order to get a tiny possibility to take your account back. These companies build on their users but, when their users need them, they betray them.
Even with 2FA, Google accounts can be hacked with just a phone number
41–50 of 128 posts
Re: Even with 2FA, Google accounts can be hacked with just a phone number
#42Earlier quoted context omitted.
Bypass 2-step to access your account but they can't change your Google password.
I responded to a comment about, "what is your plan for continuing to use your account if your phone is stolen?" Did you downvote and responded to a thread incorrectly?
Re: Even with 2FA, Google accounts can be hacked with just a phone number
#43- two factor login (you need password + sms text)
- account recovery (using only a phone) THIS IS DUMB.
I only use an alternate email for recovery (my wife and I cross). Thus, each recovery account is still 2FA secured.
There's already been a story floating around about a young kid charging his dad's credit card because of the phone recovery option (he had the android phone in this case). This is NOT the same as 2FA auth.
Re: Even with 2FA, Google accounts can be hacked with just a phone number
#44Earlier quoted context omitted.
I responded to a comment about, "what is your plan for continuing to use your account if your phone is stolen?" Did you downvote and responded to a thread incorrectly?
[deleted]
Re: Even with 2FA, Google accounts can be hacked with just a phone number
#45Re: Even with 2FA, Google accounts can be hacked with just a phone number
#46Earlier quoted context omitted.
Backup codes.
I thought that would be an answer, but then if your phone is stolen and they get in, couldn't they simply invalidate your 2fa codes too? Mind you, it's probably the best idea.
Re: Even with 2FA, Google accounts can be hacked with just a phone number
#47This sounds like an argument for adding hardware multi-factor auth in google. It's not a panacea, but a good starting point that can't be easily spoofed or hijacked.
And it adds nothing, since it still has fallbacks to the existing systems.
Re: Even with 2FA, Google accounts can be hacked with just a phone number
#48Re: Even with 2FA, Google accounts can be hacked with just a phone number
#49Earlier quoted context omitted.
Bypass 2-step to access your account but they can't change your Google password.
I responded to a comment about, "what is your plan for continuing to use your account if your phone is stolen?" Did you downvote and responded to a thread incorrectly?
(Accidentally deleted a comment of mine, this attempts to copy it)
Re: Even with 2FA, Google accounts can be hacked with just a phone number
#502. Email randomized password stored in PasswordDatabase
3. PasswordDatabase is stored in CloudDrive
4. CloudDrive randomized password stored in PasswordDatabase
5. CloudDrive with 2FA
6. PasswordDatabase secured by weak password
7. 2FA codes from 2FApp
8. PasswordDatabase, CloudDrive, Email only available together on devices with a human-friendly password. Those 3 and the 2FApp are all on the phone, secured by human-friendly password, on me always.
(How do I make 8 mathematically stronger?)