"my old Smart TV that I gave away" Gave away to whom ? Did you donate or give it to an actual person. Perhaps just ask them to log you out ? Or do you think they are a bad actor ?
Tell HN: A stranger is using my YouTube account and Google can't log them out
31–40 of 60 posts
Re: Tell HN: A stranger is using my YouTube account and Google can't log them out
#32You mentioned you have MFA activated, so you should also remove any App passwords[1] you might have created for the TV. [1] https://support.google.com/accounts/answer/185833?hl=en
Re: Tell HN: A stranger is using my YouTube account and Google can't log them out
#33What brand TV ?
Re: Tell HN: A stranger is using my YouTube account and Google can't log them out
#34You shouldn't be telling this to tier-1 support, you should be reporting it through a contact that's labeled as specifically being for reporting security issues affecting Google login, ie https://bughunters.google.com/ . This is a significant security vulnerability because the existence of this TV implies the existence of an API somewhere which the TV has used, which can create revocation-resistant keys. (I ran into…
Why shouldn't tier-1 support be able to forward this to someone who is the slightest bit technical, who can then make the call to report this to the relevant security team? There's no reason why tier-1 support has to be this irredeemably useless. Just put someone in the loop who knows when _not_ to blindly follow a script. It really isn't that hard.
Re: Tell HN: A stranger is using my YouTube account and Google can't log them out
#35You shouldn't be telling this to tier-1 support, you should be reporting it through a contact that's labeled as specifically being for reporting security issues affecting Google login, ie https://bughunters.google.com/ . This is a significant security vulnerability because the existence of this TV implies the existence of an API somewhere which the TV has used, which can create revocation-resistant keys. (I ran into…
Not really. It’s just a long lived refresh token. You can revoke the app it’s associated to but OP seems unaware.
Re: Tell HN: A stranger is using my YouTube account and Google can't log them out
#36Earlier quoted context omitted.
> I really should move off Gmail. Just curious, what's the line, if not this? Hypothetically of course, I'm okay with it if you're responding with "I'd rather not say" or "I don't know"
I’m not sure what you mean by “what’s the line” but if it means “what’s the alternative”: First start using personal domain so that when I switch away I can do it without having to update all contact details. I’ve already been doing this. Then after some research, switch to a paid email provider. I’m thinking of ProtonMail or Zoho at the moment but I need to look into it more. It’s going to be painful because I used…
One thing to note about Proton is if you want to do any shared addresses, say for family use cases, they're missing common features like aliases because of the implied encryption. I tried to switch to it a few years ago and it didn't work for all of the use cases I needed. I do pay for an account with them for other use cases and they're great otherwise. I also tried Zoho a long time ago (>8 years now) and it wasn't good at the time. I've been using FastMail for more than 7 years now and moved all my Gmail domains over about 2 years after that. I have nothing but great things to say about them and aren't affiliated in any way other than being a customer.
Re: Tell HN: A stranger is using my YouTube account and Google can't log them out
#37Earlier quoted context omitted.
I’m not sure what you mean by “what’s the line” but if it means “what’s the alternative”: First start using personal domain so that when I switch away I can do it without having to update all contact details. I’ve already been doing this. Then after some research, switch to a paid email provider. I’m thinking of ProtonMail or Zoho at the moment but I need to look into it more. It’s going to be painful because I used…
"What's the line" as in if you were to draw a line in the sand - what would be "enough" to put you over said hypothetical line of leaving GMail? I think OP may be implying that this should be "enough", but I don't want to make any assumptions. One thing to note about Proton is if you want to do any shared addresses, say for family use cases, they're missing common features like aliases because of the implied encrypti…
Re: Tell HN: A stranger is using my YouTube account and Google can't log them out
#38You shouldn't be telling this to tier-1 support, you should be reporting it through a contact that's labeled as specifically being for reporting security issues affecting Google login, ie https://bughunters.google.com/ . This is a significant security vulnerability because the existence of this TV implies the existence of an API somewhere which the TV has used, which can create revocation-resistant keys. (I ran into…
Why shouldn't tier-1 support be able to forward this to someone who is the slightest bit technical, who can then make the call to report this to the relevant security team? There's no reason why tier-1 support has to be this irredeemably useless. Just put someone in the loop who knows when _not_ to blindly follow a script. It really isn't that hard.
There is. They're probably non-Google employees, leased en-masse from the cheapest support center Google could find.
Re: Tell HN: A stranger is using my YouTube account and Google can't log them out
#39Examples of this are eBay (can still edit cart) and AliExpress (can still see unread messages count).
Perhaps YouTube has decided that appending to the watch history is a sufficiently low risk operation that it's fine to do post-logout?
Implementation-wise, I can imagine that watch history is something that might be updated from logs, and therefore there isn't an opportunity to renew any Auth tokens interactively.
Re: Tell HN: A stranger is using my YouTube account and Google can't log them out
#40You shouldn't be telling this to tier-1 support, you should be reporting it through a contact that's labeled as specifically being for reporting security issues affecting Google login, ie https://bughunters.google.com/ . This is a significant security vulnerability because the existence of this TV implies the existence of an API somewhere which the TV has used, which can create revocation-resistant keys. (I ran into…
> While our highest-impact services (e.g., Google Wallet, Gmail) are designed to make cookies expire very shortly after the user logs out, we believe that most potential exploitation vectors for this behavior fall outside the security model of modern browsers and operating systems, and can't be meaningfully mitigated by any single website.
> Check this link for more info: https://sites.google.com/site/bughunteruniversity/nonvuln/co...
Note: The issue I submitted was related to revoking all sessions (authentication) as well.