Live data from Hacker News

Even with 2FA, Google accounts can be hacked with just a phone number

ello.co

71–80 of 128 posts

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#71

Earlier quoted context omitted.

3 combined with 6 sounds like a recipe for disaster if someone manages to compromise your CloudDrive account (probably not by breaking the password, but by social engineering or a method similar to the one in this article). If they get that, they have your encrypted password database, and if that has a weak password... you're totally SOL. The password database's password is one you want to be /very/ strong.

Do you recommend I memorize a GUID? It's not quite "Correct Horse Battery Staple" Has any CloudDrive service been socially engineered? I didn't find any results in my rudimentary search.

Personally, I have a password that my password manager generated that I use for it. I had it written down in my wallet for a while, but after typing it multiple times a day for a while I memorized it and since destroyed the paper. It's a shorter password than what I use for my stored passwords, but I think it strikes a good balance. (And it's not a GUID, but if you think you could memorize that then it probably couldn't hurt. That's risky, though -- if you forget, there go all of your passwords for everything!)

I don't know of any off the top of my head, but there was that time a few years ago when Dropbox accidentally let anyone in without a password. This isn't to pick on Dropbox, but security lapses happen and it's wise to have multiple layers of strong defense to reduce your risk. (Also, if someone compromises the email associated with your CloudDrive, they can use that to get your CloudDrive by invoking a password reset.)

EDIT: Wolfram|Alpha estimates the entropy of a password generated using the constraints I used for mine as roughly 85 bits (the relevant space would take 14 trillion years to enumerate). It actually has a pretty information-heavy password strength estimator (though I can't attest to its reliability as I'm not familiar with the internals).

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#72

I work as a sales rep in-store for a telco. From a security perspective, it's ridiculous. We use computer monitors which customers face from the same angle as us. I'm sure someone thought it would make the retail scenario more inclusive, but security-wise it's a mess. I can't verify account details without pulling up those same details for the customer to see. So I ask people for their details, click the button, and…

Telco in Australia (I've worked for all of the big ones) are exactly the same as you've described.

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#73

I work as a sales rep in-store for a telco. From a security perspective, it's ridiculous. We use computer monitors which customers face from the same angle as us. I'm sure someone thought it would make the retail scenario more inclusive, but security-wise it's a mess. I can't verify account details without pulling up those same details for the customer to see. So I ask people for their details, click the button, and…

I feel bad for the telcos (and other agencies that try to keep our private info). I called up my ISP a few months back and was presented with a variety of security questions that I couldn't provide the answer to. I certainly didn't know the 4 digit passcode I created 2+ years ago and I haven't used since. My fist couple guesses on my favorite movie were wrong. It was only after my second guess of my best friend during elementary school (probably worth a blog post on the changing winds of our memory) that I was able to access my account. The problem was that I threw all sorts of answers at the customer service rep on the other end of the phone. They were willing to ignore all of my incorrect guesses in hope I would eventually hit on something they could verify. But that is exactly the problem. If I wasn't me I wouldn't want someone getting as many opportunities that I got to eventually hit the right answer to prove they are me. So where do you draw the line between customer support and customer security without either enraging real customers or allowing people to illegally access customer accounts?

TL;DR Someone create a startup to better identify people remotely.

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#74
post #67

Earlier quoted context omitted.

So you also need to make sure that your phone's browser doesn't have your Google password stored, and/or your phone's storage is encrypted with a strong-enough key.

Google has made me re-enter my password when modifying 2fa settings.

Sure, but if it's saved in the browser than it can be extracted from the browser

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#75

This is why "2FA" is supposed to actually be two factors. If you're using a phone number for 2FA, then authentication still boils down to the same thing: Something you know.

It's still two factors. If someone has only your phone but not your password, they still can't log in. The problem here is that the phone number was also used as a password recovery option, which effectively means you only need the phone to log in. I suspect most gmail users with 2FA are doing this, which defeats the purpose of 2FA. It just becomes "different factor".

It's the password recovery by phone that's the weakness. But I think people getting locked out of their own account is probably a bigger problem for Google than people getting hacked, so they err on the side of saving your from getting locked out.

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#76
post #56

What strikes me most in these stories, is how you always have to find some higher ranking company employee through personal connections in order to get a tiny possibility to take your account back. These companies build on their users but, when their users need them, they betray them.

People need to be much more aware of the fact that you don't own your gmail address, or your Twitter/Facebook/LinkedIn/Instagram/whatever account. Those companies encourage people to build their reputations and networks and "personal brands" inside their walled gardens, while repeatedly demonstrating that they won't lift a finger to help protect the user's custodianship of "their" usernames. Unfortunately - when you…

You could own bigian.bit using Namecoin I think, and use it for everything else (like your email).

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#77
post #56

What strikes me most in these stories, is how you always have to find some higher ranking company employee through personal connections in order to get a tiny possibility to take your account back. These companies build on their users but, when their users need them, they betray them.

People need to be much more aware of the fact that you don't own your gmail address, or your Twitter/Facebook/LinkedIn/Instagram/whatever account. Those companies encourage people to build their reputations and networks and "personal brands" inside their walled gardens, while repeatedly demonstrating that they won't lift a finger to help protect the user's custodianship of "their" usernames. Unfortunately - when you…

I have no doubt that if Monsanto or Goldman Sachs or Apple launched an new thing and trademarked it "Bigiain", my registrar would fold instantly to a legal demand from their lawyers

That particular problem can be solved by getting a domain that nobody else would want. In my case, I've registered my first name+last name.com, which will certainly never be considered for a trademark.

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#78
There's a balance between keeping others out and preventing yourself being locked out. Every time you add another factor, you also have to add another recovery option in case you lose that factor:

1) Password(A)

:| Hacker must break A

:| Losing A locks you out

2) Password(A) + SMS recovery(B)

:( Hacker must break A or B

:) Losing A and B locks you out

3) Password(A) + SMS(B) 2FA

:) Hacker must break A and B

:( Losing A or B locks you out

4) Password(A) + SMS(B) 2FA + SMS password recovery(B)

:| Hacker must break B

:| Losing B locks you out

5) Password(A) + SMS(B) 2FA + SMS password recovery(B) + Code sheet(C)

:( Hacker must break B or (A and C)

:) Losing B and (A or C) locks you out

6) Password(A) + SMS(B) 2FA + Code sheet(C) + 3rd channel password recovery(D)

:) Hacker must break (A and (B or C)) or (D and (B or C))

:) Losing (A and D) or (B and C) locks you out

Only the 6th option is unambiguously better than a single password. I guess using a friend's phone for password recovery and your own for 2FA would achieve that.

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#79
post #52

Earlier quoted context omitted.

Backup codes.

It's also possible to install the seed for the TOPT generator on multiple devices - all the ones I've bumped into have a mechanism for typing in a long-ish string as well as scanning a QR code - record that string (secured like a password, in something like 1Password) and you can always re-seed another device to come up with the same codes. I've got all mine on two phones and a iPad - one of the phones is usually in…

I have a similar method. When I setup 2FA on an account, I print out the QR code and scan this with the phone to verify it works. I then store the paper QR code in a safe place.

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#80
post #73

I work as a sales rep in-store for a telco. From a security perspective, it's ridiculous. We use computer monitors which customers face from the same angle as us. I'm sure someone thought it would make the retail scenario more inclusive, but security-wise it's a mess. I can't verify account details without pulling up those same details for the customer to see. So I ask people for their details, click the button, and…

I feel bad for the telcos (and other agencies that try to keep our private info). I called up my ISP a few months back and was presented with a variety of security questions that I couldn't provide the answer to. I certainly didn't know the 4 digit passcode I created 2+ years ago and I haven't used since. My fist couple guesses on my favorite movie were wrong. It was only after my second guess of my best friend durin…

A mobile carrier's identity verification could be augmented by asking questions about who you called recently.

Remote identity verification over the internet is not solved perfectly, but FIDO's U2F is pretty good. Hardware tokens cost money which most people won't buy, which is one problem. To prevent getting locked out you have to buy (and the service has to support) multiple hardware tokens, but that protects against loss or breakage. To prevent targeted token theft attacks, the token needs some kind of biometric verification (iris scans would be good), but that gets very expensive in a device that needs to be reliable and yet kept on a keychain.

That or something similar is the only way to provide verification while preventing the creation of a centralized identity database [I think a cryptographically assured identity verification system that dramatically limits identity repudiation would turn into a privacy nightmare dwarfing current identity database efforts being made by many companies]. With something U2F-like, each company or service stores their own verification seed value that is used in the future to verify you. It could be on a mobile device, like standard TOTP auth, or on a separate specialized hardware token. It could use pre-shared seed values and hashing, or nonces and asymmetric crypto.

Post reply on HN