Live data from Hacker News

Even with 2FA, Google accounts can be hacked with just a phone number

ello.co

51–60 of 128 posts

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#51
post #16

Disable SMS for 2-step and SMS for password resets and use a 2-step mobile app. https://support.google.com/accounts/answer/1066447

Indeed, as advised by telcos themselves (at least all _my_ local telcos):

http://www.itnews.com.au/News/322194,telcos-declare-sms-unsa...

'"SMS is not designed to be a secure communications channel and should not be used by banks for electronic funds transfer authentication," Stanton told iTnews this week.'

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#52

Earlier quoted context omitted.

After enabling 2FA, disabling SMS for 2-step and SMS for password resets, and ensuring that you don't have any phone number set as a way to get into you account, what is your plan for continuing to use your account if your phone is stolen?

Backup codes.

It's also possible to install the seed for the TOPT generator on multiple devices - all the ones I've bumped into have a mechanism for typing in a long-ish string as well as scanning a QR code - record that string (secured like a password, in something like 1Password) and you can always re-seed another device to come up with the same codes. I've got all mine on two phones and a iPad - one of the phones is usually in my pocket, the other is almost always at home.

As always, it's a security/convenience tradeoff - I've gone from needing "something I know and something I have" to "something I know and any one of several things I have".

Your tradeoffs there may vary - if I were a political-dissident/whistleblower/drug-czar I'd probably consider the risk of losing access altogether preferable to opening up additional avenues for vulnerabilities - an NSA-level adversary would probably have a significantly easier time if they knew they only needed to stealthily subvert one of several devices (at least one of which I don't usually have on my person) to get access to all my tfa secured assets, but the additional risk if I'm protecting myself from 4chan-grade griefers or non-network-pervasive internet criminals is - for me - low enough to accept for the additional reliability and convenience of multiple authorised tfa token generating devices.

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#53

This sounds like an argument for adding hardware multi-factor auth in google. It's not a panacea, but a good starting point that can't be easily spoofed or hijacked.

They already have it: https://support.google.com/accounts/answer/6103523?hl=en And it adds nothing, since it still has fallbacks to the existing systems.

You should be able to remove less secure authentication mechanisms via accounts.google.com, after setting up a security key

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#54
post #16

Disable SMS for 2-step and SMS for password resets and use a 2-step mobile app. https://support.google.com/accounts/answer/1066447

After enabling 2FA, disabling SMS for 2-step and SMS for password resets, and ensuring that you don't have any phone number set as a way to get into you account, what is your plan for continuing to use your account if your phone is stolen?

[deleted]

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#56

What strikes me most in these stories, is how you always have to find some higher ranking company employee through personal connections in order to get a tiny possibility to take your account back. These companies build on their users but, when their users need them, they betray them.

People need to be much more aware of the fact that you don't own your gmail address, or your Twitter/Facebook/LinkedIn/Instagram/whatever account. Those companies encourage people to build their reputations and networks and "personal brands" inside their walled gardens, while repeatedly demonstrating that they won't lift a finger to help protect the user's custodianship of "their" usernames.

Unfortunately - when you explain this to people there's no really good answer to their immediate "so what should I do?" question.

I no more "own" the bigiain.com domain than I own "bigiain" on HN, or "bigiain@gmail.com". While I can ensure I keep paying for it's registration, I have no doubt that if Monsanto or Goldman Sachs or Apple launched an new thing and trademarked it "Bigiain", my registrar would fold instantly to a legal demand from their lawyers, and I'd be just as out-in-the-cold as all those people without friends-of-friends in high enough places at Instafacetwigoo to "fix things", or with publicity platforms like @mat behind them.

I suspect in the future, there'll be a well known way to tie your online activity/reputation/network to a strong public key (with some distributed blockchain-like revocation/renewal audit trail). If anyone's working on something like that - I'd love to hear about it...

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#59

This just happened to me. The same timeframe, the same vector of attack, but a different target. They wanted my Twitter handle. Fortunately it was an old handle that Twitter had locked down and was not transferable. The hacker succeeded in making me lose my handle for a few days, but some friends came to my aid and I was able to get resolution through Twitter support. My telecom company was helpful at first, but then…

I would advise to have them write on the account that in no circumstance are they to authorize you without the passcode. This is the weakest part of the chain. We all forget our passwords.

Every cell phone carrier out there CAN NOT allow you to make changes to an account or get any personal information from an account without properly identifying yourself with an authorized name on the account, plus the last four of the account holders social OR an account PIN. If a customer can not provide these over the phone they need to visit a store with a photo ID matching the account holder to get access to the account.

Note, this isn't specific to any carrier, this is FCC regulations that poorly trained CSR's ignore.

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#60
post #52

Earlier quoted context omitted.

Backup codes.

It's also possible to install the seed for the TOPT generator on multiple devices - all the ones I've bumped into have a mechanism for typing in a long-ish string as well as scanning a QR code - record that string (secured like a password, in something like 1Password) and you can always re-seed another device to come up with the same codes. I've got all mine on two phones and a iPad - one of the phones is usually in…

[deleted]
Post reply on HN