... is reprehensible. It's a problem with the design as a whole, Google's customers are going to experience the flaw, and just passing the buck doesn't make the problem go away. I'm really disappointed in Google.
... is reprehensible. It's a problem with the design as a whole, Google's customers are going to experience the flaw, and just passing the buck doesn't make the problem go away. I'm really disappointed in Google.
Google's final response was: "[we] have filed a bug [and] will [...] take a look", see my coworker (Jeremy)'s reply from May 6 at http://static.shubh.am/2fadisclosure/google.pdf
Clearly there was initially a simple misunderstanding/miscommunication. The reporter, on April 30, gave Google a few Australian telcos presumably vulnerable. But then he clarified on May 3 that it is actually at least "a large majority of telco's in Australia and UK" that are vulnerable. So, based on this new information, Google replied "Thanks for explaining the potential scope of this issue... [we] have filed a bug".
I mean, compare this to the way it was reported to Facebook: the reporter told them right away that 2 of the top 3 telcos in Australia are vulnerable(!) Now if it had been worded like this when first reported to Google, the misunderstanding would probably not have happened.
https://www.google.com/search?q=%22Nice%20catch!%20I%27ve%20...
Not a brush-off.
I initially thought that the lack of any technical countermeasure might be a legitimate reason for Google to do nothing, but after I thought about it for a moment, I realized that when the 2FA system calls the user, it could simply prompt the user to do something before sending the verification code -- that way, the 2FA provider knows they aren't sending the code to voicemail.
Simple and effective, and later in the post I found the author and multiple companies came up with that idea on their own.