Live data from Hacker News

Tell HN: A stranger is using my YouTube account and Google can't log them out

news.ycombinator.com

31–40 of 60 posts

Re: Tell HN: A stranger is using my YouTube account and Google can't log them out

#31

"my old Smart TV that I gave away" Gave away to whom ? Did you donate or give it to an actual person. Perhaps just ask them to log you out ? Or do you think they are a bad actor ?

They're not a bad actor, I wouldn't be surprised if they have no idea they're even logged in. I actually just threw away my TV in the local drop off point. I thought it was broken beyond a point that was worth to repair but I'm guessing somebody more handy than me picked it up and DIYed it

Re: Tell HN: A stranger is using my YouTube account and Google can't log them out

#32
post #11

You mentioned you have MFA activated, so you should also remove any App passwords[1] you might have created for the TV. [1] https://support.google.com/accounts/answer/185833?hl=en

Thank you for the suggestion, I have already made sure that there are no App Passwords on my account

Re: Tell HN: A stranger is using my YouTube account and Google can't log them out

#34
post #24

You shouldn't be telling this to tier-1 support, you should be reporting it through a contact that's labeled as specifically being for reporting security issues affecting Google login, ie https://bughunters.google.com/ . This is a significant security vulnerability because the existence of this TV implies the existence of an API somewhere which the TV has used, which can create revocation-resistant keys. (I ran into…

Why shouldn't tier-1 support be able to forward this to someone who is the slightest bit technical, who can then make the call to report this to the relevant security team? There's no reason why tier-1 support has to be this irredeemably useless. Just put someone in the loop who knows when _not_ to blindly follow a script. It really isn't that hard.

I agree with you. I tried really hard to get this escalated. Tier 1 seem to have absolutely no ability to escalate tickets. It's a cost-saving decision for sure, and it feels really bad to fall between the cracks due to it

Re: Tell HN: A stranger is using my YouTube account and Google can't log them out

#35

You shouldn't be telling this to tier-1 support, you should be reporting it through a contact that's labeled as specifically being for reporting security issues affecting Google login, ie https://bughunters.google.com/ . This is a significant security vulnerability because the existence of this TV implies the existence of an API somewhere which the TV has used, which can create revocation-resistant keys. (I ran into…

Not really. It’s just a long lived refresh token. You can revoke the app it’s associated to but OP seems unaware.

Please, if I missed a method to revoke access - let me know how. I'm not being sarcastic, I think I've tried everything there is to try

Re: Tell HN: A stranger is using my YouTube account and Google can't log them out

#36
post #18

Earlier quoted context omitted.

> I really should move off Gmail. Just curious, what's the line, if not this? Hypothetically of course, I'm okay with it if you're responding with "I'd rather not say" or "I don't know"

I’m not sure what you mean by “what’s the line” but if it means “what’s the alternative”: First start using personal domain so that when I switch away I can do it without having to update all contact details. I’ve already been doing this. Then after some research, switch to a paid email provider. I’m thinking of ProtonMail or Zoho at the moment but I need to look into it more. It’s going to be painful because I used…

"What's the line" as in if you were to draw a line in the sand - what would be "enough" to put you over said hypothetical line of leaving GMail? I think OP may be implying that this should be "enough", but I don't want to make any assumptions.

One thing to note about Proton is if you want to do any shared addresses, say for family use cases, they're missing common features like aliases because of the implied encryption. I tried to switch to it a few years ago and it didn't work for all of the use cases I needed. I do pay for an account with them for other use cases and they're great otherwise. I also tried Zoho a long time ago (>8 years now) and it wasn't good at the time. I've been using FastMail for more than 7 years now and moved all my Gmail domains over about 2 years after that. I have nothing but great things to say about them and aren't affiliated in any way other than being a customer.

Re: Tell HN: A stranger is using my YouTube account and Google can't log them out

#37

Earlier quoted context omitted.

I’m not sure what you mean by “what’s the line” but if it means “what’s the alternative”: First start using personal domain so that when I switch away I can do it without having to update all contact details. I’ve already been doing this. Then after some research, switch to a paid email provider. I’m thinking of ProtonMail or Zoho at the moment but I need to look into it more. It’s going to be painful because I used…

"What's the line" as in if you were to draw a line in the sand - what would be "enough" to put you over said hypothetical line of leaving GMail? I think OP may be implying that this should be "enough", but I don't want to make any assumptions. One thing to note about Proton is if you want to do any shared addresses, say for family use cases, they're missing common features like aliases because of the implied encrypti…

Ah thanks for that. That makes sense! I'll also check out FastMail. Thanks for the recommendation :)

Re: Tell HN: A stranger is using my YouTube account and Google can't log them out

#38
post #24

You shouldn't be telling this to tier-1 support, you should be reporting it through a contact that's labeled as specifically being for reporting security issues affecting Google login, ie https://bughunters.google.com/ . This is a significant security vulnerability because the existence of this TV implies the existence of an API somewhere which the TV has used, which can create revocation-resistant keys. (I ran into…

Why shouldn't tier-1 support be able to forward this to someone who is the slightest bit technical, who can then make the call to report this to the relevant security team? There's no reason why tier-1 support has to be this irredeemably useless. Just put someone in the loop who knows when _not_ to blindly follow a script. It really isn't that hard.

> There's no reason why tier-1 support has to be this irredeemably useless.

There is. They're probably non-Google employees, leased en-masse from the cheapest support center Google could find.

Re: Tell HN: A stranger is using my YouTube account and Google can't log them out

#39
Some services still allow the less sensitive account actions after logging out.

Examples of this are eBay (can still edit cart) and AliExpress (can still see unread messages count).

Perhaps YouTube has decided that appending to the watch history is a sufficiently low risk operation that it's fine to do post-logout?

Implementation-wise, I can imagine that watch history is something that might be updated from logs, and therefore there isn't an opportunity to renew any Auth tokens interactively.

Re: Tell HN: A stranger is using my YouTube account and Google can't log them out

#40

You shouldn't be telling this to tier-1 support, you should be reporting it through a contact that's labeled as specifically being for reporting security issues affecting Google login, ie https://bughunters.google.com/ . This is a significant security vulnerability because the existence of this TV implies the existence of an API somewhere which the TV has used, which can create revocation-resistant keys. (I ran into…

I submitted a similar issue regarding Google Drive folders. I don't think submitting this issue will earn OP any money as a "significant security vulnerability": In other words, Google will not consider this a significant security vulnerability.

> While our highest-impact services (e.g., Google Wallet, Gmail) are designed to make cookies expire very shortly after the user logs out, we believe that most potential exploitation vectors for this behavior fall outside the security model of modern browsers and operating systems, and can't be meaningfully mitigated by any single website.

> Check this link for more info: https://sites.google.com/site/bughunteruniversity/nonvuln/co...

Note: The issue I submitted was related to revoking all sessions (authentication) as well.

Post reply on HN