Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
davidscoville
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
davidscoville
2mo ago
I’d like to know about algorithms that determine where elevators “rest” during downtime. In the morning maybe all rest on the ground floor. Then perhaps during midday lunch rush, some elevators rest at an average floor of where most people
2.
▲
by
davidscoville
1y ago
Yes, at least two emails. One was the spoofed email from legal@google.com (which sadly convinced me this was legit) and the other was a Google recovery code email. The spoofed email was deleted by the attacker, but I have a copy because I f
3.
▲
by
davidscoville
1y ago
I did have saved passwords in Chrome password manager but they were old. My guess is that the attacker used Google SSO on Coinbase (e.g., "sign in with Google"), which I have used in the past. And then they opened up Google's
4.
▲
by
davidscoville
1y ago
That's the big question. I've heard attackers have used Google's own tools like Google forms or Google cloud to send the email through Google's servers so it wasn't flagged. This is a major vulnerability that Google
5.
▲
by
davidscoville
1y ago
I updated the post and include the headers & html of the bounced-copy, although I don't think it's very useful.
6.
▲
by
davidscoville
1y ago
I think the attacker had my password, and they just needed a recovery method, which was the code I read over the phone. I have no idea how they had my password, I never share passwords or use the same password. But I hadn’t changed my Googl
7.
▲
by
davidscoville
1y ago
I lost the original email—the attacker deleted all evidence and then cleared my trash (and yes I tried using the Google tool to find deleted emails, but the attacker cleared that too). The reason I have this email is because I forwarded thi
8.
▲
by
davidscoville
1y ago
The code I read to them was a Google account recovery code. That’s how they accessed my Google account. I, mistakenly, believed they needed to confirm I was still alive and the rightful owner of the account. Then the attacker used Google SS
9.
▲
by
davidscoville
1y ago
Exactly. Google created vulnerabilities for the whole industry by introducing cloud synced Authenticator codes.
10.
▲
by
davidscoville
1y ago
I’ve heard scammers use Google tools like Google forms or Google cloud to send out fraudulent emails that appear like they come from Google.
11.
▲
by
davidscoville
1y ago
I believe they logged into coinbase with Google SSO. And then they used my Google Authenticator codes which were cloud synced as the second factor auth method. A warning to auth engineers: if an account is using a Gmail address, then auth c
12.
▲
Scammed out of $130K via fake Google call, spoofed Google email and auth sync
(bewildered.substack.com)
427 points
by
davidscoville
1y ago
|
648 comments