4 ms·
I mean the devices themselves. When you visit a site, details about your device are sent to the webserver, such as screen dimentions and resolution, processors
by eks391 4y ago
I mean the devices themselves.
When you visit a site, details about your device are sent to the webserver, such as screen dimentions and resolution, processors, gyroscope information (orientation of screen), location, default language, and more, so the website can cater to you - rendering it to a good fit for your screen, using a protocol that works with your GPU, with relevant ads, etc. This data is called your digital fingerprint.
Companies that deal with high security data (banks), advertising profiles (google), or bot abuse (everyone), will store the fingerprints to every device used by you on their webservers, so they know if it is a new device and to throw a captcha, 2FA, etc. I refuse to give out my number to most sites, which is sometimes the only 2FA option, so for most of my stuff, I just don't use 2FA.
Despite knowing my password and passing 5+ captchas, having a different fingerprint and not having 2FA was too much for gmail and it decided I was still not verifiable. Idk if they decided I was a user in constant attack or something, but even when I had the old laptop they were always slow to accept that I must be me, making me fill capchas everytime and reinput my password.
- jefftk 4y agoThanks! Were you able to get back in by trying again after some time had passed, or was the lockout permanent?
- eks391 4y agoI just realized you are the author! That explains your curiousity, and I'll get into the nitty gritty details. A part of my previous comment isn't clear: when I say I didnt have 2FA, I meant I didnt have it enabled at all, not that I had it enabled and lost access to it. Also I was thinking about it more, why google was always suspicious of my log ins, even before I was locked out. I remembered that my settings back then deleted cookies upon browser close, blocked 3rd party cookies and pixel trackers, but because my fingerprint matched, it appeared to google that I was on a different but similar device at every log in. When you know you password, pass the captcha, but google still doesn't trust you and you don't have 2FA, google pings every device you have that is signed into it that is on, asking you to verify that you are trying to log in on a different device. I know this well because I had to click "Yes, it's me" on my phone every time I logged into any google service on my old laptop. So that's what I meant when I didn't have my devices to confirm me. It's googles 2FA for people who don't enable it. When I degoogled, I stayed that way even till I had replaced my phone (same cell #, new device, not signed into any google service) and so google didn't recognize anything, couldn't ping me, and so it decided to just not let me in. To your question about getting back on, yes. It was awhile ago so idr what I did, but if I had to guess, I used a family members laptop that I used at some point so it had the fingerprint and cookies, and I had my password am the ability to pass captcha. Then I could verify my new laptop from there. Google still has trust issues with my laptop now that I'm even more locked down on website/browser permissions, so I have another browser with custom settings that I use so google doesn't get upset and lets me use their services when I occassionally need them. They still don't have my number and never signed into from my phone. Btw I like your article. I think you provided good tips for the causal internet user. I am curious when the day will come when phishers spoof the oAuth though. Personally I believe in security through obscurity, but to be obscure also means there can't be a streamline solution. So whatever fits each persons needs I guess.
- jefftk 4y agoThanks for the extra details! > I am curious when the day will come when phishers spoof the oAuth though. Not sure what you mean by this?
- eks391 4y agoJust generic spoofing. Like you pointed out watching for google.com.evil instead of google.com, and theres also email phishing where they try to replicate a companies email and get you to click links, etc. Theres so many ways to spoof things, and I can't imagine it being impossible to spoof oAuth. It wouldn't affect people with 2FA enabled, but for the majority of users with poor security practices or are not tech-savy it would do harm. Just off the top of my head I can think of one possible way: Send an email pretending to be a popular company, with some excuse to need an oAuth (like "Your oAuth for ImportantApp is expiring, please renew access. Act fast so you don't lose access to ImportantFeature!" Or "Our policies are changing. Please confirm oAuth to authenticate your acceptance to continue using ImportantApp") It doesnt need to be fancy, just enough to fool people who don't know that oAuth is not relevant to the email. Then they click a link in the spoofed email to the host server, with a spoofed copy of the target website. oAuth isnt going to suggest the credentials because the url is wrong, so don't ask for the credentials to the target website. Instead ask them to verify access of the website on your fake oAuth, then to confirm your decision with their gmail password. Then say it worked and redirect them to the real site. You already have their email, but now their email password as well. Automate this with bots, and then you have tons of peoples 2FA, since most peoples 2FA for website log ins is their email. Next you just do the "I forgot my username" which always asks for an associated email. Then "I forgot my password" which, on unsecure sites, also uses the email. Boom. Free accounts. Obviously there are ways to secure yourself from any basic attack like the one I just described, but for the general public that trusts tech to be flawless without their concerted effort, traps are just a matter of someone with time and motivation to make them. No trap is flawless, but there are enough people for that to not matter.