Live data from Hacker News

Adding a phone number to your Google account can make it less secure

tech.vijayp.ca

161–170 of 299 posts

Re: Adding a phone number to your Google account can make it less secure

#161
post #95
post #12

> I'm curious [...] why Google doesn’t temporarily disable accounts so impacted until a human reviews activity. Because Google doesn't have humans reviewing anything unless there's a direct link to marginal revenue/cost avoidance attached to that interaction that can be priced in. Their business model is to achieve scale through automation and machine learning; which means not doing things that would require manual i…

Yeah, maybe human review is not the most scalable solution; if data analysis shows that certain patterns of behaviour are highly predictive of an account takeover, there are almost certainly product solutions for them. I guess the real question is what the data actually show

How about "we'll review your request for $20". For recovery of email accounts and such Google could absolutely make a profit from that I feel and enable people to recover their accounts; they can surely scale a support system on that sort of funding.

Sure I can see problems with that. My initial feeling is people will thing that such support is a scam, but that at least shifts the position of Google from "we can do such support" to "we don't want people bad mouthing us so we're going to refuse to do that support even if it were prima facie profitable".

Re: Adding a phone number to your Google account can make it less secure

#162
post #26

Earlier quoted context omitted.

> This is why last weekend I moved to FastMail. I've filed two support tickets since, and both were responded to in an hour or two. Can absolutely confirm that. However, there's place for both Gmail and FastMail. Just know what you pay and what you're entitled to get for that price.

How is search in FastMail? And mobile clients?

Search seems adequate for my needs. And it works great with any IMAP email client.

Actually the strangest thing I find amazing, is FastMail's endless scrolling being basically magical. I can scroll through over 2500 messages in a folder of mine, top to bottom, instantly. It's not paginating, it's not locking up at the bottom of the first 100 to stop and load more. It :just works: in their UI.

Re: Adding a phone number to your Google account can make it less secure

#163

Recently my wife, without any identification, went to Tmobile and was able to have my account automatically canceled and added to a new joint family account. She went with my knowledge, but TMobile never called to confirm. After which my phone no longer had service, and I had to install a new sim card prior. While she did this with my knowledge, I no longer have access to make changes to the account, until she adds m…

Was there a documented and confirmed link through your banking details, like did she have the credit card that you paid for the sim with, or was she named on a joint bank account associated with your phone account?

I don't doubt that a telecom would do such a thing as you describe but have some hope that you're just not seeing the back end confirmation?

Re: Adding a phone number to your Google account can make it less secure

#164

Recently my wife, without any identification, went to Tmobile and was able to have my account automatically canceled and added to a new joint family account. She went with my knowledge, but TMobile never called to confirm. After which my phone no longer had service, and I had to install a new sim card prior. While she did this with my knowledge, I no longer have access to make changes to the account, until she adds m…

It's frightening how easy this is. Here's another example: http://www.businessinsider.com/hacker-social-engineer-2016-2

Out of curiosity, if this is done with the consent of the person whose account you're hacking (as in this example), is it illegal (considering that the corporation is also a party here)? More generally, in what circumstances can you lie on the phone about your identity without committing a crime?

Re: Adding a phone number to your Google account can make it less secure

#165
post #12

> I'm curious [...] why Google doesn’t temporarily disable accounts so impacted until a human reviews activity. Because Google doesn't have humans reviewing anything unless there's a direct link to marginal revenue/cost avoidance attached to that interaction that can be priced in. Their business model is to achieve scale through automation and machine learning; which means not doing things that would require manual i…

Like how I have more than enough information to get one of my old accounts back but their Automated Response Forms reject everything. Even the moderators on the gmail support forums rejected my claims as well and pretty much said "deal with it".

Yeah, I can't get into two of my Gmail accounts even though I have all the information it asks for. It simply doesn't work. I just want to delete them too (not even sure if that is possible), because I refuse to use Google for anything now days.

Re: Adding a phone number to your Google account can make it less secure

#166
Using a phone as a login credential is risky from a reliability point of view. At least with passwords and security questions you can (in theory) have 100% dependable access to them anywhere in the world if you memorize them, back them up, or put them on an encrypted USB flash drive or in an encrypted cloud location.

You can't do that with a phone. You can't duplicate your SIM card. If your phone is lost, broken, stolen, or your service is cut off or unavailable for whatever reason, you're screwed. At least with passwords, security questions, or hardware tokens (of which you can have several), you maintain reliable access no matter what if you've made backups.

Re: Adding a phone number to your Google account can make it less secure

#167

Using a phone as a login credential is risky from a reliability point of view. At least with passwords and security questions you can (in theory) have 100% dependable access to them anywhere in the world if you memorize them, back them up, or put them on an encrypted USB flash drive or in an encrypted cloud location. You can't do that with a phone. You can't duplicate your SIM card. If your phone is lost, broken, sto…

You can't duplicate your SIM, but your phone carrier can. In some countries, this involves them checking your government-issued ID in person, which is handy for Google as a way to outsource the ID-checking requirements.

The issue is that they don't discriminate between carriers that perform good identity checking and those that don't.

(Reliability is actually well-addressed by Google - they offer this as a supplement to the other forms of verification they provide.)

Re: Adding a phone number to your Google account can make it less secure

#169
TLDR: Telcos really are the weakest link, and you should not rely on your mobile phone number for 2FA.

Background: I have worked in IT Security at an Australian bank, and had close ties to the Internet Fraud department to help them understand fraudster's tactics.

Many banks use SMS for 2FA. Australia has a law regarding how long it should take customers to switching telco providers (called 'Porting' because your retain your phone number), and the timeframe in which this must be completed (90% within 3 hours, 99% within 2 business days). If the Telco doesn't complete in this time period, you can raise a complaint to the Telecommunications Industry Ombudsman.

Example: If you are currently with Telco A, to port your number to another company, you call Telco B and provide your details. They take care of the porting process, and you can have your service running on a new phone and SIM within 3 hours.

"All you need to have with you is your mobile number, the name of your old mobile provider, your account type (pre- or post-paid) and your account number. We'll handle the porting process from there. It can take from three hours to three days, but we try to do it as fast as we can." Source: https://www.cnet.com/au/news/switching-telcos-easier-than-yo..., 2012

To make matters worse, the fraudsters would then change the details at the new Telco B (i.e. my address is now 123 Rainbow Road, and my mother's maiden name is Smith, not Jones). When the victim called Telco B, when Telco A told them a porting request had been completed, they'd say "Sorry, we have no idea who you are and the details you're providing don't match our records". It can take days to sort the whole thing out, by which time, your Internet Banking has been compromised and funds transferred out.

This was a major problem for Australian banks, because they cover the losses for customers if you lose funds as a result of Internet Banking, as long as you weren't negligent (e.g. you left your Internet Banking logged in on a public computer in a library, or something).

If you are relying on your telephone number as a security mechanism, I would change to something else. Something you have, ideally (Google Authenticator, a physical hard token, etc.).

Sources: ACMA Porting Rules for Telcos: http://www.acma.gov.au/Industry/Telco/Numbering/Portability/... Example A: http://lifestrategies.net.au/wp-content/uploads/2015/03/Marc... Example B: http://www.itnews.com.au/news/45k-stolen-in-phone-porting-sc... Example C: http://www.news.com.au/finance/business/banking/customer-sca...

Re: Adding a phone number to your Google account can make it less secure

#170

> This pattern seems like something security software should be able to detect: a password reset with incomplete information, followed immediately by a change in recovery email, name, and two-factor-auth settings, coupled with a “my account has been compromised” help request is highly suspicious. This series of events could easily occur in legitimate cases. Say you lose or destroy your cellphone. Since you only ever…

> This series of events could easily occur in legitimate cases.

I don't think so. Why, in your scenario, would they file a help request saying the account had been compromised? They might file a request with some other content, but not that.

Your general point is valid, but I think the OP has probably figured out a set of features from which one could pretty reliably tell that something was amiss. And all he's suggesting is that such cases get bounced up to a human.

Post reply on HN