Live data from Hacker News

Bruteforcing the phone number of any Google user

brutecat.com

171–180 of 204 posts

Re: Bruteforcing the phone number of any Google user

#171

I’ve used plenty of forgot password forms before and entered my phone number to recover accounts, but I never really thought about how much information they could actually leak. It reminds me of those recovery flows from back in the day, where even just the last couple of digits of a phone number could end up being a real vulnerability for attackers. It’s surprising how something that seems harmless, like a simple re…

> It’s surprising how something that seems harmless, like a simple recovery page, can actually hide some pretty serious security risks.

This is something you should include in any personal security checkup. Attempt account recovery using every allowed mechanism. The rules for recovery change over time in a way that classical login doesn't.

Re: Bruteforcing the phone number of any Google user

#172

Earlier quoted context omitted.

Their own policies place a limit on how "demanding" they can be. Initializing a new (or power-washed) android/ChromeOS device _requires_ a Google account, so if you don't have one (or claim not to) they device initialization process will generate a new Google account for you. Even if there's no phone number or SIM card in the device. I've had a number of Android/ChromeOS devices over the years, and I've had each one…

Initializing a new (or power-washed) android/ChromeOS device _requires_ a Google account It's been a while since I've had to look at Android in any detail, but I remember that not being necessary, and a quick search online suggests that to still be the case today.

i mean yeah but then you do not have access to the play store and

Re: Bruteforcing the phone number of any Google user

#174
post #21
post #4

It must be a daunting chore to maintain all the legacy pages. The amount of now-years-old stuff that long-standing sites have to maintain, or choose to maintain, is shockingly high, and testing the combination of all that stuff is impossible. If you want an example of how diverse in age these apps are, dig around in the Gmail settings panel. Eventually you will land on a popup that uses the original Gmail look and fe…

Which is exactly why companies are aggressive about deprecating old products and services. "But why can't they just leave them running and not touch it?" Because every such service eventually becomes a security hole. The only secure code is no code.

There still is a standard password recovery flow with mail/capability URL that is reasonably safe and hasn't changed too much in a decade.

It is the bullshit some security advisories brought us that introduced new dangers. By sharing telephone numbers for example...

These threats are also worse than losing an account in many cases, because now the data can easily be correlated, which has proliferated through a lot of 2FA bullshit.

Re: Bruteforcing the phone number of any Google user

#175
post #62

This article highlights something interesting... it is quite common to get at least one /64 IPv6 block from a hosting provider or ISP. Yet most of the rate-limiting and IP blocking is done for a single IP. Sounds like when dealing with IPv6, an entire block of /64 should be rate-limited or blocked.

I'm on a relatively large Indian ISP, and my home network gets an IPv6 network assigned, which is directly routable. Didn't think about it until tailscale told me it was connecting over a direct IPv6 connection and I wondered how that was possible. Sounds like 90s network rampage may be back here.

Re: Bruteforcing the phone number of any Google user

#176

Earlier quoted context omitted.

I'd be rather surprised if IPv6 hasn't done some damage to the idea of IP blocking on the whole. It's possible, even as a residential Internet user, to request a /56 or /48 automatically with DHCPv6 Prefix Delegation. I have a /56 with Comcast. That's potentially up to 65536 /64 blocks, just from a residential user, so if you're going to attempt IP filtering for IPv6, it's got to be a lot smarter than swapping out yo…

How are you getting a /56 from Comcast? I can only request up to a /60 from them, any larger and I get a /60 rather than whatever I requested.

Good question, I checked just now and I am indeed getting only a /60. At some point in the past they gave me a /56 but no longer. I didn't notice the change because I have fewer than 16 networks, and networkd handled delegating /64s to them automatically.

Re: Bruteforcing the phone number of any Google user

#178
post #62

This article highlights something interesting... it is quite common to get at least one /64 IPv6 block from a hosting provider or ISP. Yet most of the rate-limiting and IP blocking is done for a single IP. Sounds like when dealing with IPv6, an entire block of /64 should be rate-limited or blocked.

I'm on a relatively large Indian ISP, and my home network gets an IPv6 network assigned, which is directly routable. Didn't think about it until tailscale told me it was connecting over a direct IPv6 connection and I wondered how that was possible. Sounds like 90s network rampage may be back here.

Well yes, natting is not normal on ipv6 - that’s a major feature.

Re: Bruteforcing the phone number of any Google user

#179
post #62

This article highlights something interesting... it is quite common to get at least one /64 IPv6 block from a hosting provider or ISP. Yet most of the rate-limiting and IP blocking is done for a single IP. Sounds like when dealing with IPv6, an entire block of /64 should be rate-limited or blocked.

Effectively a /64 is the new /32.

Your isp should really be giving you a /56 or /48.

Re: Bruteforcing the phone number of any Google user

#180

Earlier quoted context omitted.

they are pretty well-known as a "DMCA ignored" hosting site. Search "dmca ignored buyvm lowendtalk" and you'll find lots of forum threads of people recommending buyvm for hosting pirated content. They were also once mentioned by the RIAA for ignoring copyright law https://www.musicbusinessworldwide.com/files/2025/01/USTR-20... There's also at least one mention I can find of them hosting a CSAM website.

"Dmca ignored" is substantially not the same as "shady operators"

Why would a Canadian company care about American laws?
Post reply on HN