It's trivially easy to fake scanned documents proving that you're authorized to port a phone number from one service to another. In this case there was probably no SS7 messing about at all, just somebod falsifying the info or socially engineering his cellular carrier to transfer the number to a new phone. Mitnick's "Art of Deception" book is an authoritative resource on this problem.
Adding a phone number to your Google account can make it less secure
121–130 of 299 posts
Re: Adding a phone number to your Google account can make it less secure
#122Re: Adding a phone number to your Google account can make it less secure
#123Earlier quoted context omitted.
On the Internet? You'll get alerts that people are trying to hack you every single day. There are whole botnets that go around just trying to authenticate to everything everywhere using usernames sniffed from other hacks and every password under the sun.
I doubt they attack every single account every single day. At that point google should just ban the IPs doing that. Or at least turn of notifications for those IPs. Anyway excessive notifications are a solved problem. You can limit the notifications to one every month, and you can allow the user to disable them. But I would certainly like to know if someone tried to login to my account, and I think it would make regu…
Re: Adding a phone number to your Google account can make it less secure
#124Re: Adding a phone number to your Google account can make it less secure
#125Earlier quoted context omitted.
> We do send an email when you log in from a new device. AFTER login? or before? I need to know when someone is trying to attack me, not when they've already succeeded. Otherwise what's the point? At least if I know beforehand that someone knows my password but failed OTP check then I can change my password, right? Why does Google not tell me when this happens? It's like common sense...
On the Internet? You'll get alerts that people are trying to hack you every single day. There are whole botnets that go around just trying to authenticate to everything everywhere using usernames sniffed from other hacks and every password under the sun.
Re: Adding a phone number to your Google account can make it less secure
#126I don't think it's possible to make a Google account without a phone number anymore. It's really unfortunate, especially because I deliberately don't set up fallback contacts for my "alternate" gmail accounts, and Google keeps locking them as suspicious when I log in from a second location, and I need to "verify" with a phone number any time that happens (at which point I abandon the account). I understand that they…
When is the last time you tried? I have created a gmail account couple of weeks back without providing phone number and recovery email.
Re: Adding a phone number to your Google account can make it less secure
#127Re: Adding a phone number to your Google account can make it less secure
#128Earlier quoted context omitted.
I bet I know which one of those resources actually exists .
Google's Project Fi has great customer support. You can get someone via IM almost instantly and they also offer phone/email support. As a Fi customer, that would be my first stop if I was locked out. Good luck if you aren't a paying customer though...
Re: Adding a phone number to your Google account can make it less secure
#129> I'm curious [...] why Google doesn’t temporarily disable accounts so impacted until a human reviews activity. Because Google doesn't have humans reviewing anything unless there's a direct link to marginal revenue/cost avoidance attached to that interaction that can be priced in. Their business model is to achieve scale through automation and machine learning; which means not doing things that would require manual i…
I've actually had surprisingly good support from the $150/month plan for their cloud products. They get back to me quickly and give good advice (with custom code samples when needed).
Re: Adding a phone number to your Google account can make it less secure
#130Earlier quoted context omitted.
> Right; so instead they've built their security model around assumptions that other companies' (namely telcos) account processes are secure. That way Google can say "it's not our fault; we can't do anything about it!" No, they've built their model on the fact that for the vast majority of their users this will never be an issue. Maybe a celebrity, maybe an important target but the average user, never going to matter…
No, they've built their model on the fact that for the vast majority of their users this will never be an issue. Maybe a celebrity, maybe an important target but the average user, never going to be an issue. Email is the gateway to almost everything else. It's used for account recovery as well as (wrongly) passwords and other sensitive information. Google Drive and docs would also be compromised. It's actually a bigg…
[1] So we have two probabilities at work.