4 ms·
I just realized you are the author! That explains your curiousity, and I'll get into the nitty gritty details. A part of my previous comment isn't clear: when
by eks391 4y ago
I just realized you are the author! That explains your curiousity, and I'll get into the nitty gritty details.
A part of my previous comment isn't clear: when I say I didnt have 2FA, I meant I didnt have it enabled at all, not that I had it enabled and lost access to it.
Also I was thinking about it more, why google was always suspicious of my log ins, even before I was locked out. I remembered that my settings back then deleted cookies upon browser close, blocked 3rd party cookies and pixel trackers, but because my fingerprint matched, it appeared to google that I was on a different but similar device at every log in.
When you know you password, pass the captcha, but google still doesn't trust you and you don't have 2FA, google pings every device you have that is signed into it that is on, asking you to verify that you are trying to log in on a different device. I know this well because I had to click "Yes, it's me" on my phone every time I logged into any google service on my old laptop. So that's what I meant when I didn't have my devices to confirm me. It's googles 2FA for people who don't enable it. When I degoogled, I stayed that way even till I had replaced my phone (same cell #, new device, not signed into any google service) and so google didn't recognize anything, couldn't ping me, and so it decided to just not let me in.
To your question about getting back on, yes. It was awhile ago so idr what I did, but if I had to guess, I used a family members laptop that I used at some point so it had the fingerprint and cookies, and I had my password am the ability to pass captcha. Then I could verify my new laptop from there. Google still has trust issues with my laptop now that I'm even more locked down on website/browser permissions, so I have another browser with custom settings that I use so google doesn't get upset and lets me use their services when I occassionally need them. They still don't have my number and never signed into from my phone.
Btw I like your article. I think you provided good tips for the causal internet user. I am curious when the day will come when phishers spoof the oAuth though. Personally I believe in security through obscurity, but to be obscure also means there can't be a streamline solution. So whatever fits each persons needs I guess.
- jefftk 4y agoThanks for the extra details! > I am curious when the day will come when phishers spoof the oAuth though. Not sure what you mean by this?
- eks391 4y agoJust generic spoofing. Like you pointed out watching for google.com.evil instead of google.com, and theres also email phishing where they try to replicate a companies email and get you to click links, etc. Theres so many ways to spoof things, and I can't imagine it being impossible to spoof oAuth. It wouldn't affect people with 2FA enabled, but for the majority of users with poor security practices or are not tech-savy it would do harm. Just off the top of my head I can think of one possible way: Send an email pretending to be a popular company, with some excuse to need an oAuth (like "Your oAuth for ImportantApp is expiring, please renew access. Act fast so you don't lose access to ImportantFeature!" Or "Our policies are changing. Please confirm oAuth to authenticate your acceptance to continue using ImportantApp") It doesnt need to be fancy, just enough to fool people who don't know that oAuth is not relevant to the email. Then they click a link in the spoofed email to the host server, with a spoofed copy of the target website. oAuth isnt going to suggest the credentials because the url is wrong, so don't ask for the credentials to the target website. Instead ask them to verify access of the website on your fake oAuth, then to confirm your decision with their gmail password. Then say it worked and redirect them to the real site. You already have their email, but now their email password as well. Automate this with bots, and then you have tons of peoples 2FA, since most peoples 2FA for website log ins is their email. Next you just do the "I forgot my username" which always asks for an associated email. Then "I forgot my password" which, on unsecure sites, also uses the email. Boom. Free accounts. Obviously there are ways to secure yourself from any basic attack like the one I just described, but for the general public that trusts tech to be flawless without their concerted effort, traps are just a matter of someone with time and motivation to make them. No trap is flawless, but there are enough people for that to not matter.