Live data from Hacker News

Even with 2FA, Google accounts can be hacked with just a phone number

ello.co

41–50 of 128 posts

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#41

What strikes me most in these stories, is how you always have to find some higher ranking company employee through personal connections in order to get a tiny possibility to take your account back. These companies build on their users but, when their users need them, they betray them.

It's the Internet's version of "privatize the gains, socialize the losses." Or, the older, "Tails I win, heads you lose."

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#42
post #37

Earlier quoted context omitted.

Bypass 2-step to access your account but they can't change your Google password.

I responded to a comment about, "what is your plan for continuing to use your account if your phone is stolen?" Did you downvote and responded to a thread incorrectly?

[deleted]

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#43
This article is conflating two things:

- two factor login (you need password + sms text)

- account recovery (using only a phone) THIS IS DUMB.

I only use an alternate email for recovery (my wife and I cross). Thus, each recovery account is still 2FA secured.

There's already been a story floating around about a young kid charging his dad's credit card because of the phone recovery option (he had the android phone in this case). This is NOT the same as 2FA auth.

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#44
post #42

Earlier quoted context omitted.

I responded to a comment about, "what is your plan for continuing to use your account if your phone is stolen?" Did you downvote and responded to a thread incorrectly?

[deleted]

That requires you entering your password which shouldn't be left in plaintext on your device.

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#46

Earlier quoted context omitted.

Backup codes.

I thought that would be an answer, but then if your phone is stolen and they get in, couldn't they simply invalidate your 2fa codes too? Mind you, it's probably the best idea.

With this scheme someone can't access your account by stealing your phone. You also can't access your account by getting your phone number to point to your new phone though.

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#47

This sounds like an argument for adding hardware multi-factor auth in google. It's not a panacea, but a good starting point that can't be easily spoofed or hijacked.

They already have it: https://support.google.com/accounts/answer/6103523?hl=en

And it adds nothing, since it still has fallbacks to the existing systems.

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#48
Yet one more reason we shouldn't be letting telcos provide our phone numbers. They are painfully inadequate when it comes to security. And our mobile numbers are now probably the most important identifiers we have, due in no small part to the proliferation of SMS 2FA.

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#49
post #37

Earlier quoted context omitted.

Bypass 2-step to access your account but they can't change your Google password.

I responded to a comment about, "what is your plan for continuing to use your account if your phone is stolen?" Did you downvote and responded to a thread incorrectly?

I didn't downvote. My reply was to "other trusted devices can bypass 2factor" about yes they can access the account but they can't change the password without knowing the current password.

(Accidentally deleted a comment of mine, this attempts to copy it)

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#50
1. Email account with 2FA

2. Email randomized password stored in PasswordDatabase

3. PasswordDatabase is stored in CloudDrive

4. CloudDrive randomized password stored in PasswordDatabase

5. CloudDrive with 2FA

6. PasswordDatabase secured by weak password

7. 2FA codes from 2FApp

8. PasswordDatabase, CloudDrive, Email only available together on devices with a human-friendly password. Those 3 and the 2FApp are all on the phone, secured by human-friendly password, on me always.

(How do I make 8 mathematically stronger?)

Post reply on HN