Live data from Hacker News

Even with 2FA, Google accounts can be hacked with just a phone number

ello.co

121–128 of 128 posts

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#121
post #56

What strikes me most in these stories, is how you always have to find some higher ranking company employee through personal connections in order to get a tiny possibility to take your account back. These companies build on their users but, when their users need them, they betray them.

People need to be much more aware of the fact that you don't own your gmail address, or your Twitter/Facebook/LinkedIn/Instagram/whatever account. Those companies encourage people to build their reputations and networks and "personal brands" inside their walled gardens, while repeatedly demonstrating that they won't lift a finger to help protect the user's custodianship of "their" usernames. Unfortunately - when you…

I have been thinking about this quite a bit, recently, as well and I do think the future does look like something you described. However, I do have doubts. Outside of being worried about the big brands removing your access to your hard earned reputations (which seems unlikely on a mass scale), what would be the other common uses cases for a crypto identity key? As we know, in order for a majority of people to adopt new technologies, there has to be a very compelling use case. I am not sure a consolidated identity key solves any real problem or rather it is just a cool tech thing that us hackers would like to see, kind of similar to the problem that bitcoin in general is having in achieving adoption.

I am curious if you guys have any really good thoughts on products that could implement a crypto identity key that solves a real life problem. Would love to discuss.

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#122
post #79
post #52

Earlier quoted context omitted.

It's also possible to install the seed for the TOPT generator on multiple devices - all the ones I've bumped into have a mechanism for typing in a long-ish string as well as scanning a QR code - record that string (secured like a password, in something like 1Password) and you can always re-seed another device to come up with the same codes. I've got all mine on two phones and a iPad - one of the phones is usually in…

I have a similar method. When I setup 2FA on an account, I print out the QR code and scan this with the phone to verify it works. I then store the paper QR code in a safe place.

Or you could right-mouse save the image of the QR code as a file and then put that file on a CD-ROM or flash memory.

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#123

Earlier quoted context omitted.

You should be able to remove less secure authentication mechanisms via accounts.google.com, after setting up a security key

You still need to keep atleast one backup method in case the security key is corrupted/broken/lost etc.

You can have two or more security keys associated with your account on Google.

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#124
post #32

This is why I always recommend against using SMS-based 2-factor. Without even doing any serious research, it seemed pretty obvious to me from day one that at the very least someone like NSA/FBI could forge your number somehow with or without the carrier's help, but there's also the potential for other attackers to do it, too. Call forwarding didn't even cross my mind, but it just goes to show how ridiculously broken…

> Ideally what I'd want is an NFC ring or a smart band/watch that can use FIDO's U2F or a similar protocol that works through NFC I've got my eyes on a Yubikey NEO for just this kind of use: https://www.yubico.com/products/yubikey-hardware/yubikey-neo...

Keep your eyes on the nfc ring too http://nfcring.com

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#125

This is why "2FA" is supposed to actually be two factors. If you're using a phone number for 2FA, then authentication still boils down to the same thing: Something you know.

It's still two factors. If someone has only your phone but not your password, they still can't log in. The problem here is that the phone number was also used as a password recovery option, which effectively means you only need the phone to log in. I suspect most gmail users with 2FA are doing this, which defeats the purpose of 2FA. It just becomes "different factor". It's the password recovery by phone that's the we…

No, it's not two factors. Access to the phone number is entirely based on something you know.

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#126
post #44
post #42

Earlier quoted context omitted.

[deleted]

That requires you entering your password which shouldn't be left in plaintext on your device.

Yes, but many people leave their gmail accounts logged in. That's enough to access and disable 2factor on a laptop/desktop.

Also, what's with the downvotes?

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#127
post #44

Earlier quoted context omitted.

That requires you entering your password which shouldn't be left in plaintext on your device.

Yes, but many people leave their gmail accounts logged in. That's enough to access and disable 2factor on a laptop/desktop. Also, what's with the downvotes?

Even if you are logged into your Gmail account, Google still requires you to enter your password to disable 2-step auth.

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#128

Earlier quoted context omitted.

They already have it: https://support.google.com/accounts/answer/6103523?hl=en And it adds nothing, since it still has fallbacks to the existing systems.

You should be able to remove less secure authentication mechanisms via accounts.google.com, after setting up a security key

Oh really? I thought that it forced you to go back to the app if you use a non-U2F browser.
Post reply on HN