Live data from Hacker News

Google hacked account

news.ycombinator.com

11–20 of 169 posts

Re: Google hacked account

#11
Would be interested in knowing how they bypassed 2 factor authentication, assuming you had that enabled.

Unfortunately, it's a tough situation since for all Google or we know you could be the hacker trying to get into the account and hard for them to verify who you are, since if the hacker was able to steal person's phone to bypass 2 factor authentication, they may also have access to a copy of your drivers license or ID to send to google in an attempt to verify they are you.

While far from ideal, assuming you don't have a close friend to contact google for you via their google apps admin account, you could create a new trial google admin account and then contact google through that mentioning your situation of your other account. While they will still have to find a way to verify who you are at least you'll reach a real person.

Re: Google hacked account

#12
Unfortunately (because their services are quite good) google has no support staff. This is well known, and you should take it into account when using the services they offer.

It is not difficult to do without them.

Asking for help on HN or Reddit works sometimes, but if your business (or personal life for that matter) relies on their services you should really work towards being able to do without them.

Re: Google hacked account

#13

Would be interested in knowing how they bypassed 2 factor authentication, assuming you had that enabled. Unfortunately, it's a tough situation since for all Google or we know you could be the hacker trying to get into the account and hard for them to verify who you are, since if the hacker was able to steal person's phone to bypass 2 factor authentication, they may also have access to a copy of your drivers license o…

My mistake was that I didn't enable 2 factor authentication. I contacted them and offered to supply a copy of my password and driver license, they said the only way is to go through the dysfunctional online method to recover the password.

I did create another account, they still send the link to cancel the request to the original account!!!

Re: Google hacked account

#14

Would be interested in knowing how they bypassed 2 factor authentication, assuming you had that enabled. Unfortunately, it's a tough situation since for all Google or we know you could be the hacker trying to get into the account and hard for them to verify who you are, since if the hacker was able to steal person's phone to bypass 2 factor authentication, they may also have access to a copy of your drivers license o…

There are quite a few ways to get his SMS code if the hacker was targeting him:

http://www.zdnet.com/article/invasive-phone-tracking-new-ss7...

SMS-based 2FA is really "security through obscurity". It's "good enough" (generously said) if you happen to not piss anyone off or be someone's target. Otherwise, not so much. I don't think enabling SMS-based 2FA will pose any problem for China to hack back into OPM for instance, and yet I think that's one of their "fixes" right now.

Google's Authenticator is also useless as now Gmail allows you to bypass the Authenticator when you can't authenticate with it for whatever reason, and go straight to using SMS 2FA instead, which brings us back to point one.

Re: Google hacked account

#19

Would be interested in knowing how they bypassed 2 factor authentication, assuming you had that enabled. Unfortunately, it's a tough situation since for all Google or we know you could be the hacker trying to get into the account and hard for them to verify who you are, since if the hacker was able to steal person's phone to bypass 2 factor authentication, they may also have access to a copy of your drivers license o…

My mistake was that I didn't enable 2 factor authentication. I contacted them and offered to supply a copy of my password and driver license, they said the only way is to go through the dysfunctional online method to recover the password. I did create another account, they still send the link to cancel the request to the original account!!!

If you didn't enable 2FA, how on earth is Google or anyone for that matter able to verify it's you that owns the email address? Anyone at any time could claim they were hacked, and it's not like they require a drivers license ID when you register.

Honestly I'm not sure what Google can do here that (a) doesn't require them to now individually support users ($$$) or (b) doesn't open them up to thousands of erroneous claims.

Post reply on HN