Earlier quoted context omitted.
Except that now Google has my phone number linked to my identity too. I know this is not everyone's use case, but for those of us that care deeply about privacy, that's not a good alternative. If that's not a good counterpoint, my phone/SMS service sucks when I'm traveling abroad, which is exactly when Google thinks I'm not me. I wish Google supported TOTP like Github does, without asking for a phone number.
Are you sure that's still the case? This[1] would seem to indicate you can use a U2F device[2] as an alternative to providing a cell phone for verification. [1] https://www.google.com/landing/2step/#tab=how-it-works [2] http://googleonlinesecurity.blogspot.com/2014/10/strengtheni...
Google hacked account
161–169 of 169 posts
Re: Google hacked account
#162Re: Google hacked account
#163Earlier quoted context omitted.
Sure it does. TOTP codes are only good for X seconds Not seconds, usually a minute: https://tools.ietf.org/html/rfc6238#page-6 (This is mandated because the user could start typing at the end of a time step and/or clocks can be slightly out of sync.) and most phishing scammers merely collect the information to use much later Right. It's probably still profitable to do things in this manner because most people do not…
> Not seconds, usually a minute: Almost every service I use is 30 seconds - including Google's [1]. Even in the RFC you linked it says 30 seconds. > This is mandated because the user could start typing at the end of a time step and/or clocks can be slightly out of sync. That is the downside of TOTP. If your clock isn't in sync with the server's then you may never have a valid OTP. However, I have seen many implementa…
Hence one minute. This is also why I referred to the RFC.
The only way that would work is if you were actively watching the captured credentials and attempted to login right away. That to me would be a targeted attack rather than some random phish.
Why? It's no problem to make a phishing site that requests the password and the TOTP code and uses these credentials immediately.
Re: Google hacked account
#164Re: Google hacked account
#165Re: Google hacked account
#166Earlier quoted context omitted.
It did work for me a when I clicked from here on HN!
Yes, and this can be done in a CSRF attack on a web page like superlogout.com (don't go there if you don't want to be logged out of 20+ websites).
Re: Google hacked account
#167Earlier quoted context omitted.
If you need all the features of Gmail or Inbox, probably not. If you can get by with what IMAP has to offer, FastMail has been very solid for me. I pay about $50 a year for a single account, which can support lots (unlimited?) domains and addresses (both sending and receiving). The web UI is nice, and the iOS app is pretty good, too. They also blog a lot about what they are doing on the technical side, and seem reall…
Thanks for the suggestion, I like what they're offering. I hadn't considered spam, probably because gmail is so good at it that I haven't thought about spam in years. Anyway, seems worth a shot.