Live data from Hacker News

Google hacked account

news.ycombinator.com

161–169 of 169 posts

Re: Google hacked account

#161
post #158

Earlier quoted context omitted.

Except that now Google has my phone number linked to my identity too. I know this is not everyone's use case, but for those of us that care deeply about privacy, that's not a good alternative. If that's not a good counterpoint, my phone/SMS service sucks when I'm traveling abroad, which is exactly when Google thinks I'm not me. I wish Google supported TOTP like Github does, without asking for a phone number.

Are you sure that's still the case? This[1] would seem to indicate you can use a U2F device[2] as an alternative to providing a cell phone for verification. [1] https://www.google.com/landing/2step/#tab=how-it-works [2] http://googleonlinesecurity.blogspot.com/2014/10/strengtheni...

My guess is that you can eventually enable that, but not at first. When I click on the "get started" button, I get "Step 1: Set up your phone", with no alternative button in sight.

Re: Google hacked account

#163
post #156

Earlier quoted context omitted.

Sure it does. TOTP codes are only good for X seconds Not seconds, usually a minute: https://tools.ietf.org/html/rfc6238#page-6 (This is mandated because the user could start typing at the end of a time step and/or clocks can be slightly out of sync.) and most phishing scammers merely collect the information to use much later Right. It's probably still profitable to do things in this manner because most people do not…

> Not seconds, usually a minute: Almost every service I use is 30 seconds - including Google's [1]. Even in the RFC you linked it says 30 seconds. > This is mandated because the user could start typing at the end of a time step and/or clocks can be slightly out of sync. That is the downside of TOTP. If your clock isn't in sync with the server's then you may never have a valid OTP. However, I have seen many implementa…

However, I have seen many implementations allow for time shifting - ie the code that was generated in the past 30 seconds, this 30 seconds and the next 30 seconds are all valid.

Hence one minute. This is also why I referred to the RFC.

The only way that would work is if you were actively watching the captured credentials and attempted to login right away. That to me would be a targeted attack rather than some random phish.

Why? It's no problem to make a phishing site that requests the password and the TOTP code and uses these credentials immediately.

Re: Google hacked account

#164
https://www.emniyetevdenevenakliyat.com https://www.kayserievdeneve-nakliyat.com https://www.kayserievdenevenakliyeciler.net https://www.kayseri-evdenevenakliyat.net Eşyalarınızın büyük olması asansörlü taşınma için engel teşkil etmez.Binanız pimapen pencere olduğu müddetçe eşya büyüklüğü önemsiz kalır.Çünkü pimapen pencereleri tamamen söküyoruz. Bir şehirden öteki bir şehre nakliyat işleriniz olduğunda size nakliyat için bir zaman veririz ve bu süre içinde nakliyat işleriniz tamamlanmış olur. şehirler arası taşımacılıkta kayseri evden eve Nakliyat kalitesini yaşamak için çok sayıda seçeneğiniz var. Taşınacak eşyanın cinsi büyüklüğü ne olursa olsun Türkiye’nin bütün illerine hizmet vermekteyiz… Eşya taşıttırmak isteyen müşterilerimize sunduğumuz hizmetler arasında asansörlü eşya taşımacılığı yanı sıra anahtar teslim evden eve taşımada sunuyoruz. Firmamız kayseri melikgazi de ofisimiz kayseri ve tum turkiye evden eve nakliyat bizim işimiz Asansörlü kayseri evden eve nakliyat hizmeti şimdilerde moda olup en iyi ve kaliteli taşınma için mükemmel çözüm.Kayseri evden eve nakliyat firma elemanları olarak hizmet veren arkadaşlarımız asansör ile yapılan işlerin daha kaliteli ve güvenilir olduğunu bizimle paylaştıktan sonra artık işlerimi bu kalitede olacaktır. https://www.nevsehirevdenevenakliye.com https://www.aksarayevdenevenakliyat.biz https://www.evdenevenakliyatc.net https://www.kayserievdenevenakliyat.biz https://www.hizmetevdeneve.com https://www.kayserievdenevenakliye.net http://nigdeevdeneve-nakliyat.com/ https://www.sivasevdenevenakliyat.biz https://www.yozgatevdeneve-nakliyat.com http://www.evdenevenakliyatciler.net/

Re: Google hacked account

#165
https://www.emniyetevdenevenakliyat.com https://www.kayserievdeneve-nakliyat.com https://www.kayserievdenevenakliyeciler.net https://www.kayseri-evdenevenakliyat.net Eşyalarınızın büyük olması asansörlü taşınma için engel teşkil etmez.Binanız pimapen pencere olduğu müddetçe eşya büyüklüğü önemsiz kalır.Çünkü pimapen pencereleri tamamen söküyoruz. Bir şehirden öteki bir şehre nakliyat işleriniz olduğunda size nakliyat için bir zaman veririz ve bu süre içinde nakliyat işleriniz tamamlanmış olur. şehirler arası taşımacılıkta kayseri evden eve Nakliyat kalitesini yaşamak için çok sayıda seçeneğiniz var. Taşınacak eşyanın cinsi büyüklüğü ne olursa olsun Türkiye’nin bütün illerine hizmet vermekteyiz… Eşya taşıttırmak isteyen müşterilerimize sunduğumuz hizmetler arasında asansörlü eşya taşımacılığı yanı sıra anahtar teslim evden eve taşımada sunuyoruz. Firmamız kayseri melikgazi de ofisimiz kayseri ve tum turkiye evden eve nakliyat bizim işimiz Asansörlü kayseri evden eve nakliyat hizmeti şimdilerde moda olup en iyi ve kaliteli taşınma için mükemmel çözüm.Kayseri evden eve nakliyat firma elemanları olarak hizmet veren arkadaşlarımız asansör ile yapılan işlerin daha kaliteli ve güvenilir olduğunu bizimle paylaştıktan sonra artık işlerimi bu kalitede olacaktır. https://www.nevsehirevdenevenakliye.com https://www.aksarayevdenevenakliyat.biz https://www.evdenevenakliyatc.net https://www.kayserievdenevenakliyat.biz https://www.hizmetevdeneve.com https://www.kayserievdenevenakliye.net http://nigdeevdeneve-nakliyat.com/ https://www.sivasevdenevenakliyat.biz https://www.yozgatevdeneve-nakliyat.com http://www.evdenevenakliyatciler.net/

Re: Google hacked account

#166
post #151

Earlier quoted context omitted.

It did work for me a when I clicked from here on HN!

Yes, and this can be done in a CSRF attack on a web page like superlogout.com (don't go there if you don't want to be logged out of 20+ websites).

Wow, I'm surprised so many of these still work...

Re: Google hacked account

#167
post #57
post #45

Earlier quoted context omitted.

If you need all the features of Gmail or Inbox, probably not. If you can get by with what IMAP has to offer, FastMail has been very solid for me. I pay about $50 a year for a single account, which can support lots (unlimited?) domains and addresses (both sending and receiving). The web UI is nice, and the iOS app is pretty good, too. They also blog a lot about what they are doing on the technical side, and seem reall…

Thanks for the suggestion, I like what they're offering. I hadn't considered spam, probably because gmail is so good at it that I haven't thought about spam in years. Anyway, seems worth a shot.

I have heard it said that putting MailRoute in front of your Fastmail account, clears up the spam problem to the same degree that Google does.
Post reply on HN