28 ms·
Google hacked account
Despite Google boasting of hiring the best engineers. Their system give us mortals hope that our applications are not so bad after all.
Let me explain the pain I am going through to recover my hacked gmail account.
First, there is no way to talk to someone, their responses are canned, and to top it off, they send you to a link to submit a password request.
So far not a problem, but the email you get back after sending the password reset request contains a link to a page that allows you to cancel the request (not sure the genius who had this idea).
Now that the email is hacked, the hacker can read the emails and click to cancel the recovery process. And the vicious cycle continues.
What to do?
- BtM909 11y agoI'm assuming you've tried this: https://support.google.com/mail/answer/50270?hl=en&ref_topic=3406179 https://support.google.com/mail/answer/50270?hl=en&ref_topic.... On the other hand, it is a free service. If you'd have the business subscription, they do have a helpdesk you can contact by phone: https://www.google.com/work/apps/business/support/ https://www.google.com/work/apps/business/support/
- cbaleanu 11y agoYou can also receive a pin code via sms on your phone...
- hmoghnie 11y agoThe hacker has modified that number too
- andybak 11y agoTry posting to Hacker News in the hope someone with some authority deigns to intervene. It helps if you a high-profile blogger or known industry luminary. The prospects for the rest of us are fairly bleak.
- hmoghnie 11y agowill try, thx
- nurul 11y agohm r ask fb.com/mdnorul.islam.739
- fixermark 11y ago> The prospects for the rest of us are fairly bleak Mostly because if changing ownership of a Gmail account were as simple as "Post to Hacker News and complain," it'd be an obvious and exploitable security gap.
- andybak 11y agoI don't quite follow. I don't expect it to be easy to change ownership of an account - but there has to be a secure process that one can follow in the event. I'd be happy to pay for it. It's the fear that if the worst happened you would quite simply be unable to contact anyone that concerns me
- JacobEdelman 11y agoThat idea, if extended, could be rather entertaining. "White House Gov Account Hacked, Please Help"
- danielweber 11y agoObviously it shouldn't be as simple as "someone complained, so turn over control." However, us normal plebes should be able to get some competent human on the phone and talk to him about what's going on. I'd hop through lots of hoops to recover my google account, but without getting a human's attention I can't do anything.
- itsbits 11y agoSomeone hacked and deleted my gmail account back in 2008. And I wasn't able to create another with same name. It was like my life that time coz I had all my personal backups as mails in that one. Since then I keep a copy in my harddrive as well even when I have cloud account.
- deleted 11y ago[deleted]
- heavymark 11y agoWould be interested in knowing how they bypassed 2 factor authentication, assuming you had that enabled. Unfortunately, it's a tough situation since for all Google or we know you could be the hacker trying to get into the account and hard for them to verify who you are, since if the hacker was able to steal person's phone to bypass 2 factor authentication, they may also have access to a copy of your drivers license or ID to send to google in an attempt to verify they are you. While far from ideal, assuming you don't have a close friend to contact google for you via their google apps admin account, you could create a new trial google admin account and then contact google through that mentioning your situation of your other account. While they will still have to find a way to verify who you are at least you'll reach a real person.
- hmoghnie 11y agoMy mistake was that I didn't enable 2 factor authentication. I contacted them and offered to supply a copy of my password and driver license, they said the only way is to go through the dysfunctional online method to recover the password. I did create another account, they still send the link to cancel the request to the original account!!!
- mikegioia 11y agoIf you didn't enable 2FA, how on earth is Google or anyone for that matter able to verify it's you that owns the email address? Anyone at any time could claim they were hacked, and it's not like they require a drivers license ID when you register. Honestly I'm not sure what Google can do here that (a) doesn't require them to now individually support users ($$$) or (b) doesn't open them up to thousands of erroneous claims.
- deleted 11y ago[deleted]
- danielweber 11y agoI would prefer a system where I can pay $100 to Google to get a competent human to look at the case versus now where I can hope I have a friend of a friend to make enough noise to get someone's attention.
- y0ghur7_xxx 11y agoUnfortunately (because their services are quite good) google has no support staff. This is well known, and you should take it into account when using the services they offer. It is not difficult to do without them. Asking for help on HN or Reddit works sometimes, but if your business (or personal life for that matter) relies on their services you should really work towards being able to do without them.
- djim 11y agosimply untrue that google has zero support staff. a better statement would be they have an automated support process for free gmail accounts. they have support staff for many of their products, including the paid version of gmail.
- ceejayoz 11y agoIt'd be nice if you could pay for per-incident support on their free Gmail.
- coldpie 11y agoGenuinely asking: is there a paid email provider roughly on par with Google's offerings in terms of usability and uptime? I'd consider switching.
- batou 11y agoMicrosoft actually do a good job and you can always call someone who can actually do something. Never thought I'd say that. However, I'm using an IMAP box on Gandi.net and a domain purchased elsewhere and that is it. I refuse to use any services tied to a single company any more. This change has given me a lot of headspace for other things.
- fixermark 11y agoThat seems phishable. I wonder what method Microsoft uses to verify that I'm not calling in to steal someone's account.
- deleted 11y ago[deleted]
- q3k 11y agoIt's a free service. You get what you pay for.
- GnarfGnarf 11y agoI think it's more accurate to say that you don't get what you don't pay for. Did the folks who bought Worldcom stock get what they paid for? Enron? Bre-X?
- creyer 11y agoI guess is all about: how can you prove you're not the hacker?
- raverbashing 11y agoLocation of past IPs used to access GMail Knowledge about items on the inbox/address book Location of devices used to access the account Knowledge of past passwords Not sending password reset emails to secondary emails that have just been added
- danielweber 11y agoIf a human looks it would be trivial for me to do the legwork to prove I own the google account. I've had more than one job that uses gmail in the office, including my current one. My boss's account is presumably authenticated and if I bugged him he would vouch for my identity. I have correspondence with a bunch of people in my google account going back years. I could bug any number of them to vouch for me. I've had, in the past, a few work accounts that used google, that mad my picture associated with it. I can do a google hangout to show that that is still my face. I have a driver's license with my real name on it, which matches my google account. I control the phone number associated with my google account. . . . A hacker could compromise one or two of those, but it would be hard for him to get a majority of them, even if he had my phone and email in his control.
- FredericJ 11y agoThe issue is that you're not Google's client. Maybe buy something from them (a large amount of ads), then try to get support?
- cainoniac 11y agoRemember: We're not Google's clients, we're Google's products
- benihana 11y agoPlease stop repeating this intellectually lazy and false meme. Or go to reddit; platitudes that don't require critical thinking tend to do better there.
- MDCore 11y agoYour best bet at stopping a false meme is to replace it with a better one. What do you recommend?
- RHSeeger 11y agoI would go with > You're not Google's product, you're their supplier; one of their many millions of suppliers. Their product is your personal information, which you supply to them in exchange for their services. The fact that you are one of many millions of suppliers (each dealing in microtransactions) means you don't have a lot of weight when you need to get help from them.
- finnjohnsen2 11y agoYou had two step verification, or not? I'm hoping you'll say no, because my feeling of security comes from the fact I've enabled TSV.
- flanbiscuit 11y agosecond this! Hope it's a no
- danieldk 11y agoWhat kind of two factor authentication? TOTP codes don't protect you against e.g. phishing. A MITM can request codes and forward them (since they are time-based). Get a U2F key. They work with Google accounts and provide much better protection against phishing (the phishing site does not have the key handle and cannot initiate the challenge-response as a result): https://www.yubico.com/products/yubikey-hardware/fido-u2f-security-key/ https://www.yubico.com/products/yubikey-hardware/fido-u2f-se...
- artursapek 11y agoI love my Yubikey! I use it with all my Google accounts.
- salibhai 11y agoAny benefit to Yubikey over Authenticator? EDIT: good points here: https://bitcointalk.org/index.php?topic=159444.0 https://bitcointalk.org/index.php?topic=159444.0
- danieldk 11y agoThis is old. They old Yubikeys with HOTP provided some advantages over authenticator, but new Yubikeys provide U2F which is much more resilient against phishing attacks. https://www.yubico.com/applications/fido/ https://www.yubico.com/applications/fido/ Moreover, U2F does not present itself as a USB keyboard (which had security implications on X11, since every application can listen in on keyboard events.)
- praalka 11y agothey went full microsoft
- JupiterMoon 11y agoStrangly hotmail does a better job here...
- GFischer 11y agoExactly the opposite, Microsoft might have worse services but their support is excellent.
- frosttt 11y agoDid you post on the gmail forums?
- ceejayoz 11y agoI'm a little baffled at the idea that the forums would be able to resolve this sort of thing.
- praalka 11y agothey went full microsoft
- w8rbt 11y agoIf your account is part of Google Apps for Education, or some other managed Google Apps account, you should contact your Google Apps admin. If it's just a normal Google account, I'm not sure there's much more that you can do. Email is the most sought after account. All the password reset requests to your Bank, Twitter, Facebook, etc. are delivered to your email account. So when someone steals your email account, they've stolen all the others too. Go change those accounts to use your new email (if you can).
- hmoghnie 11y agoyou are absolutely right.
- frosttt 11y agoHave you tried the forums? If so, could you point me to the post, please?
- topynate 11y agoHm, I'd try timing the request so that it's the middle of the night wherever the thief lives. Try once assuming that he lives in America, once assuming Eastern Europe.
- deadmik3 11y agoThis may not be the quickest result, but the basic idea of just trying & trying & trying... until you eventually beat the hacker sounds almost like a game.
- Implicated 11y agoUnless they've scripted the process to open password reset emails and follow the cancel link.
- yandie 11y ago> So far not a problem, but the email you get back after sending the password reset request contains a link to a page that allows you to cancel the request (not sure the genius who had this idea) Did you set the recovery email the same as the main email? Cause I only get password reset to the recovery email. If you used the same address for recovery email, then it defeats the whole purpose
- hmoghnie 11y agono i set another email. but still both emails will get the link.
- deleted 11y ago[deleted]
- giarc 11y agoIs the person that hacked the account just sitting there waiting for emails to come in and hopefully can click the "Cancel Request" before you can reset the password?
- mark-r 11y agoIf you make a habit of hacking Gmail accounts, it's probably not hard to make a bot that does it for you.
- DannyBee 11y agoThis is not correct. Or at least, it should not be AFAIK. I actually just tried it on an account I own, and it does not send the email to both addresses, only to the recovery email address. If that is really happening to you, that sounds like a bug to me.
- ruanmartinelli 11y agoAdding to discussion: once I tried changing a corworker's gmail password just for fun (he was right beside me and doubted that I could) by just providing few ordinary information I knew about him (e-mail lists we were both subscribed to, e-mail from our boss, other coworkers, etc). Well, I was able to change his password to a completely new one. Very concerning, not sure if it still remains that easy.
- aseemraj 11y agoGoogle sends the recovery information related emails on the recovery email address. So they won't be going to the account that is not accessible to you (I prefer to say that instead of hacked). And the link to cancel the request is indeed a good idea, because if someone else submits a password reset request, then you must be able to cancel it because you did not initiate it. Otherwise, you will end up losing your account to the real initiator of the request.
- Adiminstrator 11y agoHello, I believe i can help.
- Tepix 11y agoNow that's just cruel.
- kazinator 11y ago> What to do? The first step would be to edit the title of your submission to begin with "Ask HN: hacked Google account, what to do?", since you're asking a question. "Google hacked account" means, to an English speaker, that Google perpetrated hacking against some account somewhere (subject-verb-object, right?) E.g. Google people gained access to your bank account. I.e. your current submission title is clickbait.
- philtar 11y agoThat's the least relevant thing you can tell someone with 130+ points and 60+ comments.
- bitmapbrother 11y agoWith all due respect, your very misleading title gave the impression that Google security was hacked when in reality you were hacked either by social engineering, using a very weak password or not using 2 factor authentication.
- myth_buster 11y agoI visited because I misinterpreted the title and I think grandfather comment shows that it's not an exception.
- deleted 11y ago[deleted]
- jokr004 11y agoYour nitpicking isn't helping anyone.
- myth_buster 11y agoIt would be helpful to many who will misinterpret and be visiting now that the thread is on front page.
- smtddr 11y agoNitpicking? I had no idea what this submission was even about. I thought maybe Google, the company, was hacked by outsiders. That was my best guess. Or even "Google hacked" could imply "Hacked by Google", I don't even know. The current title is ambiguous at best; just plain misleading/sensational at worse - especially now reading that this is really about just one person losing access to their Gmail. _____ EDIT: In case the title does get changed, the original title that I'm looking at right now is "Google hacked account". This is what I woke up to this morning --- http://i.imgur.com/vWJ41ck.png http://i.imgur.com/vWJ41ck.png
- chintan 11y agoedge case - scheduled for sprint # 5642
- brightball 11y agoIf they're going to have cancel password change requests they also have to have cancel change of alternative email requests. That's the first thing a hacker changes. Additionally, you have to track every change with a timestamp so that you can invalid everything that came AFTER the change you just reset. That will prevent a hacker from being able to screw with the account because the original email address will also be able to cancel future changes, no matter how many times the perpetrator did it.
- black-perl 11y agoAnd, the loop continues. Can't they reset your gmail account. Yes they can ! Ask them explaining the problem.
- rghose 11y agoI guess you just need to be faster than the person who hacked your account. Just before the cancel link is clicked you gotta make your move. Yeah, and the cancel request was a total stroke of genius!
- pbhjpbhj 11y agoI imagine that Google would allow the "cancel request" to override recent password alterations to avoid accounts being taken over simply because the cracker moved faster than the owner once it was realised the Google account was cracked/accessed. It may not be enough to run a password update before they act on the email. It also may not be physically possible if they have a script watching for such emails from Google and cancelling the request immediately, you'd then need to set up a faster method and/or receive the email before they did.
- cmdrfred 11y agoHacker != Guy who phished your password
- pooooooop90900 11y agoHi I'm a secret agent of sleepy town
- timruffles 11y agoFor next time: pay for google apps.
- sombremesa 11y agoIf they are automatically clicking these links you may be able to spoof an E-mail that looks similar to the password reset request but have the cancel link actually log them out. Going to this URL logs you out on Gmail: https://accounts.google.com/Logout?service=mail&continue=https://mail.google.com/mail&hl=en https://accounts.google.com/Logout?service=mail&continue=htt... This might not work, but it's probably worth a try.
- umurkontaci 11y agoIt did work for me a when I clicked from here on HN!
- Aissen 11y agoYes, and this can be done in a CSRF attack on a web page like superlogout.com (don't go there if you don't want to be logged out of 20+ websites).
- anilgulecha 11y agoThis is nice :) Certainly helpful when using a public machine. Heck .. make that the homepage on browser-launch on public machines and guest accounts.
- toxicFork 11y agoWow, I'm surprised so many of these still work...
- bingobob 11y agoif you get your account back i would look at setting up 2-Step Verification https://support.google.com/accounts/answer/180744?hl=en https://support.google.com/accounts/answer/180744?hl=en
- mark_l_watson 11y agoGoogle provides some great services, but support is lacking. I suggest, for the future: 1) use two factor authorization 2) use a separate email service because email is so important that you need the best support, etc. that you can get (I use Fastmail) 3) periodically download your Google data so if you ever need to set up a new Google account, you have some of your old context I do still use GMail, but as a backup email. I am going to start teaching free Internet security and privacy classes at my local library so I have been thinking a lot about these issues. Google, Facebook, Twitter, etc. provide really nice services, but it is important to consider privacy issues and have a plan for using these "free" services.
- hiou 11y agoI would see if you can upgrade your gmail to a paid account and then contact their support. Free accounts get very little attention but paid accounts will get you to a real person eventually.
- rogeryu 11y agoGreat - but that only works if you have access to the account. Otherwise I could take over any account by simply paying? I guess Google is smarter than that.
- jmilloy 11y agoI agree that Google's help services are lacking. I never got my account back years ago. But this sounds fishy to me. It's equally likely that you are trying to hack someone else's account as trying to recover your own. There's nothing wrong with the password reset process. However, isn't there a process for when you suspect your account has been compromised? Have you even tried that? Are you even sure that your account has been compromised, or you just can't remember your password? I like that us hackers are happy to help, and happy to commiserate with the failings of big corporations, but I think it's worthwhile to be a bit sceptical. Edit: I'll add that the claim that the reset requests are going to the original account and being cancelled is fishy. We have verification in this thread that this in fact does not happen, and presumably the OP can't access the account to make a truthful counter claim.
- frosttt 11y agoYou can try here. https://productforums.google.com/forum/#!forum/gmail https://productforums.google.com/forum/#!forum/gmail
- hellbanner 11y agoA while back, I was chatting with someone on gTalk who I had pissed off in a forum. The next time I tried to sign in, my password has changed. I had to do the reset.. when I signed back in, no signs of foreign IP access was there. My best guess: malware on the forum OR they exploited a vuln on Gmail.com similar to how hotmail.com & yahoo.com used to be very very vulnerable..
- philbo 11y agoThis actually happened to me a few years back and, eventually, they were very helpful. The key for me was providing sufficient proof that the account really was mine and really had been hacked. I gave them as much information as I could remember/check: * some contact names * some tag names * some recent thread subjects/recipients * name of the person who first invited me to GMail back in the day * details of any labs settings, theme etc * mailing list subscriptions I wish I could remember the email address I used to get in touch with them but, as I said, this was years ago now. I definitely found it somewhere publicly available, albeit buried somewhat. HTH
- EGreg 11y agoThe right way for these companies to restore your account would be several of the contacts you've added long ago to verify that it is indeed you, in some way a machine can use, such as you signing in with your OLD credentials (which are kept around), filling out a form with their contact details (which were in the addressbook on the service and to which you have sent at least a few emails long ago) and them forwarding you the generated keys to your email by some method they choose to reach you -- only by collecting 4 or 5 of these keys could anyone unlock the account. Presumably you choose the people to whom you've reached out another way and explained how to tell you the code to activate your email. This is like an alternative to two-factor communication. It can only be defeated by someone actually hacking your account and then convincing 3-4 of your close friends to send him the keys to your account when you start the dispute. I'm a big fan of using information obtained easily and casually in the course of doing something productive (like often emailing someone) for good purposes. PS: I have disclosed it publicly on this date so no patenting! :-)
- deleted 11y ago[deleted]
- pooooooop90900 11y agoCool
- resulemniyet 11y agohttps://www.emniyetevdenevenakliyat.com https://www.emniyetevdenevenakliyat.com https://www.kayserievdeneve-nakliyat.com https://www.kayserievdeneve-nakliyat.com https://www.kayserievdenevenakliyeciler.net https://www.kayserievdenevenakliyeciler.net https://www.kayseri-evdenevenakliyat.net https://www.kayseri-evdenevenakliyat.net Eşyalarınızın büyük olması asansörlü taşınma için engel teşkil etmez.Binanız pimapen pencere olduğu müddetçe eşya büyüklüğü önemsiz kalır.Çünkü pimapen pencereleri tamamen söküyoruz. Bir şehirden öteki bir şehre nakliyat işleriniz olduğunda size nakliyat için bir zaman veririz ve bu süre içinde nakliyat işleriniz tamamlanmış olur. şehirler arası taşımacılıkta kayseri evden eve Nakliyat kalitesini yaşamak için çok sayıda seçeneğiniz var. Taşınacak eşyanın cinsi büyüklüğü ne olursa olsun Türkiye’nin bütün illerine hizmet vermekteyiz… Eşya taşıttırmak isteyen müşterilerimize sunduğumuz hizmetler arasında asansörlü eşya taşımacılığı yanı sıra anahtar teslim evden eve taşımada sunuyoruz. Firmamız kayseri melikgazi de ofisimiz kayseri ve tum turkiye evden eve nakliyat bizim işimiz Asansörlü kayseri evden eve nakliyat hizmeti şimdilerde moda olup en iyi ve kaliteli taşınma için mükemmel çözüm.Kayseri evden eve nakliyat firma elemanları olarak hizmet veren arkadaşlarımız asansör ile yapılan işlerin daha kaliteli ve güvenilir olduğunu bizimle paylaştıktan sonra artık işlerimi bu kalitede olacaktır. https://www.nevsehirevdenevenakliye.com https://www.nevsehirevdenevenakliye.com https://www.aksarayevdenevenakliyat.biz https://www.aksarayevdenevenakliyat.biz https://www.evdenevenakliyatc.net https://www.evdenevenakliyatc.net https://www.kayserievdenevenakliyat.biz https://www.kayserievdenevenakliyat.biz https://www.hizmetevdeneve.com https://www.hizmetevdeneve.com https://www.kayserievdenevenakliye.net https://www.kayserievdenevenakliye.net http://nigdeevdeneve-nakliyat.com/ http://nigdeevdeneve-nakliyat.com/ https://www.sivasevdenevenakliyat.biz https://www.sivasevdenevenakliyat.biz https://www.yozgatevdeneve-nakliyat.com https://www.yozgatevdeneve-nakliyat.com http://www.evdenevenakliyatciler.net/ http://www.evdenevenakliyatciler.net/
- resulemniyet 11y agohttps://www.emniyetevdenevenakliyat.com https://www.emniyetevdenevenakliyat.com https://www.kayserievdeneve-nakliyat.com https://www.kayserievdeneve-nakliyat.com https://www.kayserievdenevenakliyeciler.net https://www.kayserievdenevenakliyeciler.net https://www.kayseri-evdenevenakliyat.net https://www.kayseri-evdenevenakliyat.net Eşyalarınızın büyük olması asansörlü taşınma için engel teşkil etmez.Binanız pimapen pencere olduğu müddetçe eşya büyüklüğü önemsiz kalır.Çünkü pimapen pencereleri tamamen söküyoruz. Bir şehirden öteki bir şehre nakliyat işleriniz olduğunda size nakliyat için bir zaman veririz ve bu süre içinde nakliyat işleriniz tamamlanmış olur. şehirler arası taşımacılıkta kayseri evden eve Nakliyat kalitesini yaşamak için çok sayıda seçeneğiniz var. Taşınacak eşyanın cinsi büyüklüğü ne olursa olsun Türkiye’nin bütün illerine hizmet vermekteyiz… Eşya taşıttırmak isteyen müşterilerimize sunduğumuz hizmetler arasında asansörlü eşya taşımacılığı yanı sıra anahtar teslim evden eve taşımada sunuyoruz. Firmamız kayseri melikgazi de ofisimiz kayseri ve tum turkiye evden eve nakliyat bizim işimiz Asansörlü kayseri evden eve nakliyat hizmeti şimdilerde moda olup en iyi ve kaliteli taşınma için mükemmel çözüm.Kayseri evden eve nakliyat firma elemanları olarak hizmet veren arkadaşlarımız asansör ile yapılan işlerin daha kaliteli ve güvenilir olduğunu bizimle paylaştıktan sonra artık işlerimi bu kalitede olacaktır. https://www.nevsehirevdenevenakliye.com https://www.nevsehirevdenevenakliye.com https://www.aksarayevdenevenakliyat.biz https://www.aksarayevdenevenakliyat.biz https://www.evdenevenakliyatc.net https://www.evdenevenakliyatc.net https://www.kayserievdenevenakliyat.biz https://www.kayserievdenevenakliyat.biz https://www.hizmetevdeneve.com https://www.hizmetevdeneve.com https://www.kayserievdenevenakliye.net https://www.kayserievdenevenakliye.net http://nigdeevdeneve-nakliyat.com/ http://nigdeevdeneve-nakliyat.com/ https://www.sivasevdenevenakliyat.biz https://www.sivasevdenevenakliyat.biz https://www.yozgatevdeneve-nakliyat.com https://www.yozgatevdeneve-nakliyat.com http://www.evdenevenakliyatciler.net/ http://www.evdenevenakliyatciler.net/
- 9931323781 11y agoI WANT TO CHAIRMAN OF GOOGLE
- 9931323781 11y agoMY AIM IS ALL INDIA RANK 1st in IIT JEE AND IChallange 95%MARKS IN BIHAR BOARD EXAMINTION IN 2016