Not Getting Hacked
jefftk.com
jefftk.com
No, don’t ever do this.
1. Google or Facebook or Apple now know everywhere you have an account
2. If they choose to disable your access to their service (as happens regularly and without due process), you can’t login to any website.
I am curious why you say blocked accounts happens regularly. I have heard of it happening to people, but not often.
HN is littered with people who’ve experienced Google bans. An article hits the front page about it seemingly monthly (and those are only the ones that get publicized). It happens again and again. You have no recourse. There is no one to call. There is never an explanation.
I’m not here to convince you. To each his own. If you dont care about the privacy leaks, then surely you can overlook the risk of losing access to your non-Google accounts whenever Google decides.
Sure, for the few sites I care deeply about a long history with, a unique account might be worth it. Those sites are few and far between.
My password manager has more than 500 entries. A huge majority are sites I used once and never again. I don't want an account there but was probably required to create one to check out. If Google deleted them they'd be doing me a favor. Google knows I went to those sites anyway since I probably found them through search results.
I dont care.
The only services important for me are: bank, email and hosting. Losing my gh would suck but it is not serious
The rest of services I treat as "nice to have"
My accounts on them are irrelevant for me. Losing account on random forum, random game, some streaming platform wouldnt change my life. I would just create a new one.
It would suck, but thats not important
I think avoiding the situation you ran into, however, is a very different question. How likely you are to get locked out for security reasons depends a lot on what security configuration you choose. The big risk here is that you set up 2FA and then lose access to your second factor. If someone were to follow the approach I advocate in the post, of always maintaining three registered security keys and adding a new one if you lose an old one, I think the risk of a security lockout ends up being super low.
Do you mean you had a phone number configured in the account but it was out of date, or something else?
When you visit a site, details about your device are sent to the webserver, such as screen dimentions and resolution, processors, gyroscope information (orientation of screen), location, default language, and more, so the website can cater to you - rendering it to a good fit for your screen, using a protocol that works with your GPU, with relevant ads, etc. This data is called your digital fingerprint.
Companies that deal with high security data (banks), advertising profiles (google), or bot abuse (everyone), will store the fingerprints to every device used by you on their webservers, so they know if it is a new device and to throw a captcha, 2FA, etc. I refuse to give out my number to most sites, which is sometimes the only 2FA option, so for most of my stuff, I just don't use 2FA.
Despite knowing my password and passing 5+ captchas, having a different fingerprint and not having 2FA was too much for gmail and it decided I was still not verifiable. Idk if they decided I was a user in constant attack or something, but even when I had the old laptop they were always slow to accept that I must be me, making me fill capchas everytime and reinput my password.
A part of my previous comment isn't clear: when I say I didnt have 2FA, I meant I didnt have it enabled at all, not that I had it enabled and lost access to it.
Also I was thinking about it more, why google was always suspicious of my log ins, even before I was locked out. I remembered that my settings back then deleted cookies upon browser close, blocked 3rd party cookies and pixel trackers, but because my fingerprint matched, it appeared to google that I was on a different but similar device at every log in.
When you know you password, pass the captcha, but google still doesn't trust you and you don't have 2FA, google pings every device you have that is signed into it that is on, asking you to verify that you are trying to log in on a different device. I know this well because I had to click "Yes, it's me" on my phone every time I logged into any google service on my old laptop. So that's what I meant when I didn't have my devices to confirm me. It's googles 2FA for people who don't enable it. When I degoogled, I stayed that way even till I had replaced my phone (same cell #, new device, not signed into any google service) and so google didn't recognize anything, couldn't ping me, and so it decided to just not let me in.
To your question about getting back on, yes. It was awhile ago so idr what I did, but if I had to guess, I used a family members laptop that I used at some point so it had the fingerprint and cookies, and I had my password am the ability to pass captcha. Then I could verify my new laptop from there. Google still has trust issues with my laptop now that I'm even more locked down on website/browser permissions, so I have another browser with custom settings that I use so google doesn't get upset and lets me use their services when I occassionally need them. They still don't have my number and never signed into from my phone.
Btw I like your article. I think you provided good tips for the causal internet user. I am curious when the day will come when phishers spoof the oAuth though. Personally I believe in security through obscurity, but to be obscure also means there can't be a streamline solution. So whatever fits each persons needs I guess.
> I am curious when the day will come when phishers spoof the oAuth though.
Not sure what you mean by this?
Just off the top of my head I can think of one possible way: Send an email pretending to be a popular company, with some excuse to need an oAuth (like "Your oAuth for ImportantApp is expiring, please renew access. Act fast so you don't lose access to ImportantFeature!" Or "Our policies are changing. Please confirm oAuth to authenticate your acceptance to continue using ImportantApp") It doesnt need to be fancy, just enough to fool people who don't know that oAuth is not relevant to the email. Then they click a link in the spoofed email to the host server, with a spoofed copy of the target website. oAuth isnt going to suggest the credentials because the url is wrong, so don't ask for the credentials to the target website. Instead ask them to verify access of the website on your fake oAuth, then to confirm your decision with their gmail password. Then say it worked and redirect them to the real site. You already have their email, but now their email password as well. Automate this with bots, and then you have tons of peoples 2FA, since most peoples 2FA for website log ins is their email. Next you just do the "I forgot my username" which always asks for an associated email. Then "I forgot my password" which, on unsecure sites, also uses the email. Boom. Free accounts.
Obviously there are ways to secure yourself from any basic attack like the one I just described, but for the general public that trusts tech to be flawless without their concerted effort, traps are just a matter of someone with time and motivation to make them. No trap is flawless, but there are enough people for that to not matter.
It's not about security. It's about that the oAuth protocol relies on good faith providers. Google is demonstrably not a good faith provider in terms of tracking. Part of oAuth includes refreshing that token and validating it with the provider.
> I am curious why you say blocked accounts happens regularly.
As for the blocked accounts bit, it's not so much the frequency that matters. It's that Google has zero and I mean literally zero humans to contact if their security machine flags your account for something. Their appeals process is a joke and a bad one at that.
If you're searching for frequency, use Algolia to get an idea of how many people have appealed to this site: https://hn.algolia.com/?q=Google+blocked+account
Next, load up the Googler and search Twitter and Reddit for the same thing. There's a lot of occurrences, horror stories, and news articles about it. Google does not care about addressing this.
83 results, and the first page has like one actual appeal from a person?
There are still cases where individuals' accounts get banned randomly (and if there's enough ruckus, reinstated), which I've posted about there. And thinking about it, it might be the case that developer accounts with $$$ invested in them might just be the most likely to post on HN and complain, while individuals just suffer Google's "support" and give up. In any case, they're not as easily visible as the dev account bans, so we don't know how often they occur (unless someone trawls through support.google.com posts and creates a list of such).
Most normies don’t get locked out because they don’t use 2fa, don’t change devices and use a single easy to remember (probably easily guessable) password for every account.
Getting locked out of google is most likely the result of using security best practices like installing a 2fa app on a device that gets lost. Or a misplaced yubi key, etc…
Good advice is to print out one time use codes, and store them somewhere safe, like a safe. Physical security is much better in a digital world than digital security.
If you and/or your password manager are tricked and enter your username and password, all other 2FA methods are vulnerable to an active pishing attack where the attacker site relays the login information to the real site in real time. You enter your TOTP code or hit "yes" on a push notification or whatever, the real site logs you in and passes your session cookie to the attacker and you're hacked.
With a security key when you log in the browser tells the key what website you're connecting to and about its TLS certificate. If the security key wasn't registered with it exactly, it won't work.
It's almost impossible* to get phished if you use a security key as your 2FA method.
* There are few ways. If you're phished during first time setup of the security key, or if the attacker gets a valid TLS cert for their website and impersonates accounts.google.com with a network level attack, or if they manage to get a trusted private CA onto your machine and do the same, or if they can exploit a 0day in the browser or the key to disrupt that communication and lie to the security key about the site's identity. But the bar for these forms of attacks is significantly higher.
Untrusted executable code that's expected to be a modified version of the real thing, making hash-based assurances impossible in most cases. Sounds secure to me. /s
It's kind of sad, in the days prior to torrents security used to be reputation-based. Not to mention a dynamic where reversers look at each other's work. Since the advent of torrents and with just the sheer amount of games now, I imagine that's suffered quite a bit.
Some forms of DRM are arguably malware in and of themselves, so it's ironic that attempts at bypassing that end up as a vector for serious malware.
What worries me is since Steam opened its floodgates, theoretically lesser-known titles could be vectors for malicious code. Or heck, even larger titles. What assurances are there, actually? Trust in the publisher and developer is about it.
I'd rather be very specific in suggesting password managers, use them only for non-critical services.
> You're overestimating people's ability to create strong master password and the efforts needed in cracking a password.
Okay - so we're establishing that many people use insecure passwords. Password managers mitigate this risk completely by generating incredibly secure passwords - however, people may use an insecure master password.
> I'd rather be very specific in suggesting password managers, use them only for non-critical services.
And your proposed solution is for people to use NO secure passwords, but to use their poor password creation abilities on every site they use.
This only leads to people using insecure passwords _everywhere_, rather than in one, local file, which is far less likely to be attacked.
Which doesn't work well in a multi-devices landscape as the one we live in for many people (even if not the majority, because the majority probably just owns and uses a smartphone).
I don't use cloud password managers, history has shown it is too risky.
- firstly tie ourself to a service is the best thing to do to get lock-out of something "belonging to us" but not under our control, A TOTAL NO GO. We need to own, in person, not give something to others pockets "because their are safer";
- secondly I do not want to use ANY not-personal password managers and recent attacks prove very well why;
- thirdly the most simplest form of being "locked out" is that a service we depend on does not work anymore, the simplest form of protection is NOT depending on third parties.
Have your own files, on personal hw, with offline LOCAL copies and a good backup strategy (of course on encrypted storage, but that might prevent a thief access the information NOT ensure the availability of something) is a good lock-out prevention. Having a personal mail infra is hard, but owning a domain name and have a LOCAL mailserver at home that just use someone else service as a replica ensure you have the mails and the domain, being "locked out" means just being offline until you restore, still being able to read your mails and eventually move your domain somewhere else and that's far less harder. Having a personal website instead of using some platform is another nice way, especially if you advertise you have also a ZeroNet and similar P2P systems copy, so even if the website is hosted by some provider your readers know there is a LIVE copy in a P2P distributed system and eventually they even have a local copy.
Protecting a company or even a sole personal computer is a time staking challenge with multiple dimensions. It involves implementing processes and routines which you stick to, it involves technical solutions for mitigating threats in different categories and it involves planning, configuration and monitoring.
It certainly involves staying well informed on vulnerabilities, present threats and the modus operandi of attackers.
That's why we security consultants (on a senior level) are more or less useless unless we are developers ourselves and stack 30 000 + hours in experience. And still, with all this experience and knowledge the work is not a piece of cake at all.
You have to be prepared to make exceptions, be pragmatic, a good communicator and a good skilled presenter. You have to be prepared to work uncomfortable hours, holidays, weekends etc.
(EDIT: To everyone saying this is a bad idea: yes I agree, and that's unrelated to my question. Before reading my subsequent paragraph, note this sentence can be interpreted two different ways. I thought it meant "automatically" as in "without needing to manually copy-paste" (to avoid phishing), but it seems maybe the intention was "without prompting the user"? The second one seems like bad advice and not what I was asking about regardless - I'm asking about the anti-phishing fill where the program enters the text, NOT about unprompted filling, which I already agree is a bad idea.)
It's not this simple in reality is it? Surely it's not just me whose password manager often has to prompt to fill in a legit website it can't recognize, because the domain or URL isn't the same as what it has stored in its database? Are non-technically-inclined folks expected to be able to follow this advice in practice?
Leaking one site could allow someone access into another site. For example, if I've integrated API keys from one site into another. It is those sorts of targets that hackers really look for.
Not entirely true. If the site requires your login in order to, say, decrypt your server side data, then even if the site is compromised, your data is still secure, until you log in. I'm making this up as a possibility, I've never seen or heard of a site that actually did that.
Regardless, I'd rather error on the side of caution. There are too many things that I don't know about here that could be possible. Automatically filling in my password somewhere seems like an obvious thing to be cautious about.
Protonmail maybe ;-)
For the very reason he mentions down the page :
>Use tools so you can't mess up even if you're not paying attention.
*Note its worth noting that this hotkey combo only works on sites that you have logged against that password. it wont just blurt out the next password.
Every password manager I've used associates those credentials with a URL. One of my accounts used to get them confused, because the company offered a dedicated login page and login via the home page on separate subdomains.
So that feature might make it harder to get phished by adding friction. And if an attacker has malicious code running on the legitimate website, how would you know?
Personally, I use 1Password without any browser extension and I choose to copy/paste my password from the 1Password app into the password field on a website. Usually I type the username/email manually.
If my clipboard is compromised, then an attacker will get only the password for only the current website. They won't even know the username or website it's associated with.
On the other hand, if a browser extension for my password manager is compromised, the impact could be much more severe and widespread. In some scenarios an attacker could read my entire vault.
Also, if my clipboard is compromised, then probably so is my entire OS, in which case all my browser extensions are too.
This is my personal preference, but frankly I think it's just bad advice to use a browser extension with your password manager, and especially bad advice to use one with auto-filling behavior.
there is no silver bullet. we need a lot common sense and not preaching in absolute terms.
i would counter with don't use cloud based password managers. i'd go so far as don't use cloud based anything, but that ship has sailed. i use a password manager, but do not use the cloud offerings of it. i can sync all of my devices to the same database, but yes i have to do it. >99% of people will prefer the convenience over security, so as a founding father once said, give them neither (or something like that).
You can always export your passwords, they're not locked into a password manager.
One thing you can do to mitigate is to set up WebAuthn 2FA for the password manager as well. If your master password somehow leaks (say, a keylogger), the attacker still cannot access the vault since they don't have access to your security key.
Local storage: it’s a thing.
Using TOTP 2FA should be the primary second factor enforced everywhere. If you use Aegis on android or Raivo for ios, you control your 2FA secrets and can make encrypted cloud backups. I can't see myself ever using YubiKeys or Passkeys because I don't want to worry about hardware failure. Additionally, the chrome/ios roll out of passkeys requires it to be associated with your Google/Apple account and is tied to your login. Google passkeys don't support linux and don't plan to.
Veracrypt is stable and replaced truecrypt for me years and years ago. I am not sure why bitlocker would be recommended over Veracrypt. For true full-disk encryption, I thought it was still best to use a BIOS/UEFI set password so the prompt happens before boot. My understanding is that this is independent of OS. From the last time I checked, bitlocker has slightly better OS integration, but veracrypt allows compatibility and decryption with linux. I like veracrypt for situations where I need things to be portable and able to be backed up in the cloud or need access across OSes. Is there a benefit in using bitlocker?
I like GitHub's push in this area. When ssh keys were first being forced for signing/authentication for commits, I was annoyed that I couldn't use passwords. But I realized that I was more annoyed about having to change my workflow, and it doesn't slow me down now that I've done it a few times.