Live data from Hacker News

Bruteforcing the phone number of any Google user

brutecat.com

151–160 of 204 posts

Re: Bruteforcing the phone number of any Google user

#151
post #62

This article highlights something interesting... it is quite common to get at least one /64 IPv6 block from a hosting provider or ISP. Yet most of the rate-limiting and IP blocking is done for a single IP. Sounds like when dealing with IPv6, an entire block of /64 should be rate-limited or blocked.

Even that isn’t sufficient, as it’s very easy to get ahold of /48 blocks. To do a good job of this, you need to actually break things down by ASN and look at their policies for handing out IP addresses to figure out what granularity to use.

Re: Bruteforcing the phone number of any Google user

#152
post #90

Earlier quoted context omitted.

This is why I don't use a real phone number with any of these services. They don't need my phone number to operate either.

g has been demanding a valid phone for years, as have most other major providers. if you lose the number you sign up with, you can potentially get locked out of the account. whats your mo?

I currently have three actively used gmail accounts that all date from the initial "word of mouth" referral from another user days. I once had many gmail accounts that I spun up for a project mapping spam to disposable accounts, etc.

Not one of these emails ever had a phone number attached. The current gmail accounts I use also have no phone number associated, whenever I'm asked to attach a phone number for recovery or security I decline.

As none of these were ever signed up from a phone number there's no phone number to lose, in the event of a security challenge I verify from an associated gmail account.

There's little to no trace of my birth certificate name, phone number, actual address of my house, etc. on the internet .. the few people who do push through on that kind of back tracking invariably end up with a relative or a different but similar West Australian.

Re: Bruteforcing the phone number of any Google user

#153
post #90

Earlier quoted context omitted.

This is why I don't use a real phone number with any of these services. They don't need my phone number to operate either.

g has been demanding a valid phone for years, as have most other major providers. if you lose the number you sign up with, you can potentially get locked out of the account. whats your mo?

If you didn't sign up with a number in the first place, they like to request that you add one, but you can just skip it.

Re: Bruteforcing the phone number of any Google user

#154
post #108
post #91

Earlier quoted context omitted.

The information is transferred through a method called "communication" by another human.

OP originally pitched the website clean up work providing a way to learn about the company, its products, history, etc. If something is obvious, sure, but how is the new intern even going to know when to ask?

Being able to do this is a marketable skill. It’s one thing to write it but quite another to correct it

Re: Bruteforcing the phone number of any Google user

#156

[flagged]

There are problems which are difficult to solve even with immense computing power, which will confuse even powerful LLMs, but which humans can easily solve. That won't require JS, yet be a big obstacle to attackers. IMHO the biggest reason why such solutions aren't more widely deployed is because the incumbent wants to keep its effective browser monopoly.

can be easily exploited by script kiddies using large proxy networks

Such a scheme would need a large amount of LLMs or actual (intelligent) humans too.

Google clearly wanted to make account recovery accessible even without JS

Unfortunately, they made authentication require JS.

Re: Bruteforcing the phone number of any Google user

#157

I’m mostly impressed that he can throw 40k requests per second at a server for a prolonged period and not somehow spike the resources enough to set off some alarms.

For comparison, Google apparently processes about 160k search queries per second.

Re: Bruteforcing the phone number of any Google user

#158
I’ve used plenty of forgot password forms before and entered my phone number to recover accounts, but I never really thought about how much information they could actually leak. It reminds me of those recovery flows from back in the day, where even just the last couple of digits of a phone number could end up being a real vulnerability for attackers. It’s surprising how something that seems harmless, like a simple recovery page, can actually hide some pretty serious security risks.

Re: Bruteforcing the phone number of any Google user

#159

Earlier quoted context omitted.

g has been demanding a valid phone for years, as have most other major providers. if you lose the number you sign up with, you can potentially get locked out of the account. whats your mo?

Their own policies place a limit on how "demanding" they can be. Initializing a new (or power-washed) android/ChromeOS device _requires_ a Google account, so if you don't have one (or claim not to) they device initialization process will generate a new Google account for you. Even if there's no phone number or SIM card in the device. I've had a number of Android/ChromeOS devices over the years, and I've had each one…

Initializing a new (or power-washed) android/ChromeOS device _requires_ a Google account

It's been a while since I've had to look at Android in any detail, but I remember that not being necessary, and a quick search online suggests that to still be the case today.

Re: Bruteforcing the phone number of any Google user

#160
post #66

Earlier quoted context omitted.

This is why I use things like Firefox Relay's email/phone masking for sites and services I don't trust. Would be interested if people know of free alternatives, as the phone mask requires their premium plan, and that can be a no-go for friends and family.

It helps somewhat, but unless you give a unique number to every single friend, business, bank, store, your real number will find its way into data breaches sooner or later. Heck AT&T and T-Mobile have themselves had large scale hacks in the last few years.

I mean it's better than nothing :/ Firefox's mobile mask is only one number, but I haven't seen any better alternatives. I do think I get significantly less spam/scam calls and texts than everyone else I know. But even if you had a unique number per service, I don't think that'll stop them entirely. If you've ever had to get a new number, as you say, it's probably already leaked somewhere whether or not you share it anywhere.
Post reply on HN