Live data from Hacker News

Even with 2FA, Google accounts can be hacked with just a phone number

ello.co

81–90 of 128 posts

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#81
"and every so often, I would get authorization code texts for the Gmail account that was tied to my Instagram handle"

As far as I know these authorization texts are only sent when your Gmail username and password have been entered correctly. This would indicate that the attacker knew your long random password. Keylogger? From there they only need your 2fa to access your account.

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#83
This article brings up a question about protecting email addresses that I'm hoping a HN reader can answer.

I have a unique email address for PayPal--different from my normal email address--that I want to keep secret. The problem is that every time I make a purchase, the merchant gets this email address (in addition to the normal email address I gave to the merchant). I know that merchants get it because I get junk mail at my secret PayPal address from merchants I did business with.

Is there no way to make a PayPal payment without PayPal handing my email address over to the merchant?

As a related question, why do I have to trust the merchant to redirect me to PayPal's website to make the payment? There are many ways I can get fooled into entering my PayPal password directly into merchant's website (for example, the merchant opens the PayPal site in a frame or pop-up, so you can't verify that it's really PayPal). Isn't there a way I can open my own browser window, login to PayPal, and give some sort of invoice number to PayPal to direct payment to the merchant?

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#85
post #56

Earlier quoted context omitted.

People need to be much more aware of the fact that you don't own your gmail address, or your Twitter/Facebook/LinkedIn/Instagram/whatever account. Those companies encourage people to build their reputations and networks and "personal brands" inside their walled gardens, while repeatedly demonstrating that they won't lift a finger to help protect the user's custodianship of "their" usernames. Unfortunately - when you…

I have no doubt that if Monsanto or Goldman Sachs or Apple launched an new thing and trademarked it "Bigiain", my registrar would fold instantly to a legal demand from their lawyers That particular problem can be solved by getting a domain that nobody else would want. In my case, I've registered my first name+last name.com, which will certainly never be considered for a trademark.

Depends. What is your first and last name?

I require your address, SSN, mother's maiden name and the name of your first pet to verify your answer.

Thank you, have a great day!

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#86

Earlier quoted context omitted.

I have no doubt that if Monsanto or Goldman Sachs or Apple launched an new thing and trademarked it "Bigiain", my registrar would fold instantly to a legal demand from their lawyers That particular problem can be solved by getting a domain that nobody else would want. In my case, I've registered my first name+last name.com, which will certainly never be considered for a trademark.

Depends. What is your first and last name? I require your address, SSN, mother's maiden name and the name of your first pet to verify your answer. Thank you, have a great day!

I have no idea why are you asking me that or why was I downvoted. I said nothing about identity verification, just trademark issues. Seriously, wtf?

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#87
post #76
post #56

Earlier quoted context omitted.

People need to be much more aware of the fact that you don't own your gmail address, or your Twitter/Facebook/LinkedIn/Instagram/whatever account. Those companies encourage people to build their reputations and networks and "personal brands" inside their walled gardens, while repeatedly demonstrating that they won't lift a finger to help protect the user's custodianship of "their" usernames. Unfortunately - when you…

You could own bigian.bit using Namecoin I think, and use it for everything else (like your email).

> .bit is a top-level domain that was created outside of the most commonly used domain name system of the Internet, and is not sanctioned by ICANN

Ah so it doesn't work for probably 99+% of the the internet

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#88

Earlier quoted context omitted.

Backup codes.

I thought that would be an answer, but then if your phone is stolen and they get in, couldn't they simply invalidate your 2fa codes too? Mind you, it's probably the best idea.

Put a strong password on the phone. Not just a PIN. Touch ID makes that practical now.

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#89
So is the takeaway that we should all disable SMS-based options for receiving 2FA codes, because it weakens your 2FA to the level of your (non-2FA) cell phone account?

I think when I enabled iCloud 2FA it included 2 channels for communication with my phone: one as a named iOS device (where the OS handles receiving and displaying codes), and another as just its phone number. Is that for SMS? Why would they even do that?

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#90
post #56

What strikes me most in these stories, is how you always have to find some higher ranking company employee through personal connections in order to get a tiny possibility to take your account back. These companies build on their users but, when their users need them, they betray them.

People need to be much more aware of the fact that you don't own your gmail address, or your Twitter/Facebook/LinkedIn/Instagram/whatever account. Those companies encourage people to build their reputations and networks and "personal brands" inside their walled gardens, while repeatedly demonstrating that they won't lift a finger to help protect the user's custodianship of "their" usernames. Unfortunately - when you…

I think it's a good idea to own your own domain name, at least as a tech savvy user. You can still use Google Apps with it (Google for work now?).

That being said, I think it's a bit unfair to say companies won't lift a finger to help protect their users usernames. On the technical security level, many companies put a lot of effort into things like 2F, general internet security, etc. In particular Google, but also Dropbox, github, and others. On the service level (i.e. what happens when you have to talk to someone) everybody could probably improve quite a bit. OTOH that's costly and would ultimately need to be paid for by the customers somehow.

On the legal level, there isn't really anything these companies could do for you. If you do not own a trademark for your chosen domain name (account name, page name, ...), you'll lose it to someone who does [0]. That also won't change if you have all kinds of friends in all kinds of places - your problem then is basic trademark law, not the goodwill of some company (that has to adhere to the law, after all).

Disclaimer: I work for Google.

[0] possibly with the exception of the account or domain name being your legal name, but I don't think there's a general norm for that.

Post reply on HN