Live data from Hacker News

Even with 2FA, Google accounts can be hacked with just a phone number

ello.co

111–120 of 128 posts

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#113
post #81

"and every so often, I would get authorization code texts for the Gmail account that was tied to my Instagram handle" As far as I know these authorization texts are only sent when your Gmail username and password have been entered correctly. This would indicate that the attacker knew your long random password. Keylogger? From there they only need your 2fa to access your account.

If I'm not mistaken, the attacker set call/msg forwarding on his phone via his telco and then they chose the "forgot my password" option where a SMS text from Google (now going to attacker's phone) can be used to reset the password.

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#114

Earlier quoted context omitted.

They already have it: https://support.google.com/accounts/answer/6103523?hl=en And it adds nothing, since it still has fallbacks to the existing systems.

You should be able to remove less secure authentication mechanisms via accounts.google.com, after setting up a security key

You still need to keep atleast one backup method in case the security key is corrupted/broken/lost etc.

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#115
post #87
post #76

Earlier quoted context omitted.

You could own bigian.bit using Namecoin I think, and use it for everything else (like your email).

> .bit is a top-level domain that was created outside of the most commonly used domain name system of the Internet, and is not sanctioned by ICANN Ah so it doesn't work for probably 99+% of the the internet

I'm just letting him know that the thing he envisions for the future already exists. We just have to convince browser vendors to embrace it.

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#116

This is why I always recommend against using SMS-based 2-factor. Without even doing any serious research, it seemed pretty obvious to me from day one that at the very least someone like NSA/FBI could forge your number somehow with or without the carrier's help, but there's also the potential for other attackers to do it, too. Call forwarding didn't even cross my mind, but it just goes to show how ridiculously broken…

Why would the FBI/NSA bother with that when whoever is doing the auth will probably give them whatever they ask for directly anyways?

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#117
At least now, more people will accurately describe it as two-step verification rather than two-factor authentication.

They are entirely different. If SMS OTPs were actually 2FA, the hacker would have needed to steal the phone too.

The difference between two-step verification & two-factor authentication. https://ramblingrant.co.uk/the-difference-between-two-factor...

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#118
post #101
post #89

So is the takeaway that we should all disable SMS-based options for receiving 2FA codes, because it weakens your 2FA to the level of your (non-2FA) cell phone account? I think when I enabled iCloud 2FA it included 2 channels for communication with my phone: one as a named iOS device (where the OS handles receiving and displaying codes), and another as just its phone number. Is that for SMS? Why would they even do tha…

Yes. Not everyone using a Mac has an iOS device.

Yeah but why would they do it when they know that number is registered to an iOS device? Why the double entry? (Perhaps it's a fluke in my case.)

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#119
post #36

Earlier quoted context omitted.

Simply stealing your phone isn't enough. They also need to know your password change 2-step settings.

Last I checked, this was not the case- And a major cause for concern.

Everytime I go to https://www.google.com/settings/security and click on 2-step verification, I'm required to enter my password if I haven't done so in the last 5 min or so.

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#120

Earlier quoted context omitted.

You should be able to remove less secure authentication mechanisms via accounts.google.com, after setting up a security key

You still need to keep atleast one backup method in case the security key is corrupted/broken/lost etc.

Print out a recovery code and keep it somewhere safe.
Post reply on HN