Live data from Hacker News

Google hacked account

news.ycombinator.com

121–130 of 169 posts

Re: Google hacked account

#121
post #34

> So far not a problem, but the email you get back after sending the password reset request contains a link to a page that allows you to cancel the request (not sure the genius who had this idea) Did you set the recovery email the same as the main email? Cause I only get password reset to the recovery email. If you used the same address for recovery email, then it defeats the whole purpose

no i set another email. but still both emails will get the link.

This is not correct. Or at least, it should not be AFAIK.

I actually just tried it on an account I own, and it does not send the email to both addresses, only to the recovery email address.

If that is really happening to you, that sounds like a bug to me.

Re: Google hacked account

#122
I agree that Google's help services are lacking. I never got my account back years ago. But this sounds fishy to me.

It's equally likely that you are trying to hack someone else's account as trying to recover your own. There's nothing wrong with the password reset process.

However, isn't there a process for when you suspect your account has been compromised? Have you even tried that? Are you even sure that your account has been compromised, or you just can't remember your password?

I like that us hackers are happy to help, and happy to commiserate with the failings of big corporations, but I think it's worthwhile to be a bit sceptical.

Edit: I'll add that the claim that the reset requests are going to the original account and being cancelled is fishy. We have verification in this thread that this in fact does not happen, and presumably the OP can't access the account to make a truthful counter claim.

Re: Google hacked account

#123

Earlier quoted context omitted.

My mistake was that I didn't enable 2 factor authentication. I contacted them and offered to supply a copy of my password and driver license, they said the only way is to go through the dysfunctional online method to recover the password. I did create another account, they still send the link to cancel the request to the original account!!!

If you didn't enable 2FA, how on earth is Google or anyone for that matter able to verify it's you that owns the email address? Anyone at any time could claim they were hacked, and it's not like they require a drivers license ID when you register. Honestly I'm not sure what Google can do here that (a) doesn't require them to now individually support users ($$$) or (b) doesn't open them up to thousands of erroneous cl…

[deleted]

Re: Google hacked account

#124
post #120

I would see if you can upgrade your gmail to a paid account and then contact their support. Free accounts get very little attention but paid accounts will get you to a real person eventually.

Great - but that only works if you have access to the account. Otherwise I could take over any account by simply paying? I guess Google is smarter than that.

Re: Google hacked account

#125

If they are automatically clicking these links you may be able to spoof an E-mail that looks similar to the password reset request but have the cancel link actually log them out. Going to this URL logs you out on Gmail: https://accounts.google.com/Logout?service=mail&continue=htt... This might not work, but it's probably worth a try.

It did work for me a when I clicked from here on HN!

Re: Google hacked account

#127
A while back, I was chatting with someone on gTalk who I had pissed off in a forum. The next time I tried to sign in, my password has changed. I had to do the reset.. when I signed back in, no signs of foreign IP access was there.

My best guess: malware on the forum OR they exploited a vuln on Gmail.com similar to how hotmail.com & yahoo.com used to be very very vulnerable..

Re: Google hacked account

#128

Earlier quoted context omitted.

What kind of two factor authentication? TOTP codes don't protect you against e.g. phishing. A MITM can request codes and forward them (since they are time-based). Get a U2F key. They work with Google accounts and provide much better protection against phishing (the phishing site does not have the key handle and cannot initiate the challenge-response as a result): https://www.yubico.com/products/yubikey-hardware/fido-…

I love my Yubikey! I use it with all my Google accounts.

So what happens when you lose that?

Re: Google hacked account

#129
post #114

Earlier quoted context omitted.

What kind of two factor authentication? TOTP codes don't protect you against e.g. phishing. A MITM can request codes and forward them (since they are time-based). Get a U2F key. They work with Google accounts and provide much better protection against phishing (the phishing site does not have the key handle and cannot initiate the challenge-response as a result): https://www.yubico.com/products/yubikey-hardware/fido-…

> What kind of two factor authentication? TOTP codes don't protect you against e.g. phishing. Sure it does. TOTP codes are only good for X seconds and most phishing scammers merely collect the information to use much later (I have seen the source behind the actual phishing sites). I have yet to hear of a story of someone's account being compromised while using TOTP (knock on wood). But seriously though - companies li…

Sure it does. TOTP codes are only good for X seconds

Not seconds, usually a minute:

https://tools.ietf.org/html/rfc6238#page-6

(This is mandated because the user could start typing at the end of a time step and/or clocks can be slightly out of sync.)

and most phishing scammers merely collect the information to use much later

Right. It's probably still profitable to do things in this manner because most people do not use any second factor. That does not change the fact that TOTP is extremely vulnerable to phishing. Most people here could probably a code that does this live in an hour or so.

But seriously though - companies like Google, Facebook, Gandi, Dropbox, and Microsoft all use TOTP.

Yes, because TOTP adds good security against other attacks, such as password leaks, since every site has its own shared secret.

Re: Google hacked account

#130
post #98

> What to do? The first step would be to edit the title of your submission to begin with "Ask HN: hacked Google account, what to do?", since you're asking a question. "Google hacked account" means, to an English speaker, that Google perpetrated hacking against some account somewhere (subject-verb-object, right?) E.g. Google people gained access to your bank account. I.e. your current submission title is clickbait.

Your nitpicking isn't helping anyone.

Nitpicking? I had no idea what this submission was even about. I thought maybe Google, the company, was hacked by outsiders. That was my best guess. Or even "Google hacked" could imply "Hacked by Google", I don't even know.

The current title is ambiguous at best; just plain misleading/sensational at worse - especially now reading that this is really about just one person losing access to their Gmail.

_____

EDIT: In case the title does get changed, the original title that I'm looking at right now is "Google hacked account". This is what I woke up to this morning --- http://i.imgur.com/vWJ41ck.png

Post reply on HN