4 ms·
This is why EVERYONE should have Two-Step Verification (https://support.google.com/accounts/answer/180744?hl=en https://support.google.com/accounts/answer/18074
by juliann 13y ago
This is why EVERYONE should have Two-Step Verification (https://support.google.com/accounts/answer/180744?hl=en https://support.google.com/accounts/answer/180744?hl=en) enabled if you care a little bit about your Google Account and the data you have stored there. This kind of attack will expose your password, but the attackers wont get in your account anyway.
- deleted 13y ago[deleted]
- wtvanhest 13y agoI have it, but one thing to consider when you add Two-step is that you need a plan when you travel overseas and may not have the same sim card. Not difficult to consider, but you still need to. Being in Europe for a few weeks with no email is no fun.
- juliann 13y agoThe two step app works even with no connection to the internet. I dont know how but it does. I think you dont need to have the same sim card. only the phone turned on.
- herge 13y agoI think that the two step code is a hash of a random number shared between Google and the app (when reading the QR code), and the current time.
- tjohns 13y agoGoogle Authenticator uses TOTP (RFC 6238), which means the codes are a function of time plus a secret key. As long as your phone's clock is reasonably accurate, the app will work without any network access. http://tools.ietf.org/html/rfc6238 http://tools.ietf.org/html/rfc6238
- UnfalseDesign 13y agoYou definitely don't need network access. I use Google Authenticator on my Wifi only tablet. You need an internet connection to sync it to Google's key but not after that. And, yes, when the tablet's clock is off by a few minutes, the code doesn't work.
- teraflop 13y agoThat's not a problem if you use the Authenticator app (or a compatible alternative) instead of getting codes over SMS.
- greyskull 13y agoIn that case, use the one-time backup codes and make sure to refresh them every few logins while you're away. I think they give you eight at a time.
- anon1385 13y agoSerious question: what if you don't have a mobile phone?
- axyjo 13y agoGoogle provides you access to one-time codes, if you wish.
- deletes 13y agoI thought you were joking. Sign in using backup codes: https://support.google.com/accounts/answer/1187538?hl=en https://support.google.com/accounts/answer/1187538?hl=en
- eli 13y agoThere's a compatible OTP app for nearly every OS. Ideally you'd be running it on a device that isn't the same as the one running your web browser, but you could just install e.g. a Windows OTP app and use that. Better than nothing.
- shirKahn 13y agoPersonally I use a phone, but I also own a TI Chronos programmable watch that has Google OTP support. The algorithm is fairly straightforward and does not require internet connectivity (through mathematical magic).
- freehunter 13y agoInteresting, I hadn't come across that watch before. How do you like it? Can you compare it to something like a Pebble: size, battery life, screen quality, etc?
- skj 13y agoI don't understand how 2FA completely counters this scam. Consider if you called someone up and told them your password, and then gave them an up-to-date number from your OTP generator. Except instead of calling them up, you're entering it into a fake web page. Certainly the login you just made would not work when you opened up gmail in another window, but all necessary information would have been given to the attacker.
- juliann 13y agoFirst, the scam would be randomly asking for the code or not. Cause it can't know whether the user has 2FA activated or not. So that is one way of noticing that its a scam. 2nd the code only works for 30 seconds or so. I don't know if there's some way of login in through google api's as soon as the user enters the user and password. Also im almost sure that google requires you to enter the code via a form that is provided by them (as a google url). So im thinking something like loggin in to google using server side code and somehow using the code that the user provides to enter into google form (that will be displayed on the server side). Im still not sure if there's any way of doing this using code. If there's no way of doing it using code then the attacker should be fast enough to use your logins and token in less than 30 seconds (or even less when the code is entered later). So it reduces the chances to get attacked a lot.
- euank 13y agoA sophisticated attack can completely imitate 2FA. The first bit: It starts by asking for a username+pass and it uses javascript to async-post it. The evil server then tries to login to google. If google returns that a 2FA is needed it prompts for it. I have no clue what you mean by "through google's api"... An attacker does not have to follow an api. Anything the user can do with their browser, the attacker an imitate on a remote server. Absolutely anything except source ip. Your entire "no way of doing this using code" makes no sense at all. Posting data is something that can easily be done programmatically. Posting data through a middleman is similarly easy. The only way that 2FA helps (edit: as alcari points out, this doesn't help much) is that the attacker can't change your password because on initiating that, I believe google asks for another 2FA code, and I don't think the attacker could reasonably expect to get you to enter two 2FA in a row. It also does make it harder for the attacker to code it up, but it's not even that much harder.
- ikarandeep 13y agoAgreed 100% However, hopefully you aren't using the same password on other sites. And hopefully you don't plan to use the same password on other sites in the future.