HNHacker News
TopNewBestAskShowJobs

davidscoville

180 karma · joined August 16, 2017

submissionscomments
davidscoville··on Show HN: Elevators
I’d like to know about algorithms that determine where elevators “rest” during downtime. In the morning maybe all rest on the ground floor. Then perhaps during midday lunch rush, some elevators rest at an average floor of where most people got off in the morning. In the evening when people go home, maybe most elevators rest higher up where most people are.
davidscoville··on Scammed out of $130K via fake Google call, spoofed Google email and auth sync
Yes, at least two emails. One was the spoofed email from legal@google.com (which sadly convinced me this was legit) and the other was a Google recovery code email.

The spoofed email was deleted by the attacker, but I have a copy because I forwarded the email to phishing@google.com (something ChatGPT told me to do). The attacker then deleted the original but when I got my account back an hour later, Google bounced back the email. So that is the copy I have and the headers are not super helpful.

davidscoville··on Scammed out of $130K via fake Google call, spoofed Google email and auth sync
I did have saved passwords in Chrome password manager but they were old. My guess is that the attacker used Google SSO on Coinbase (e.g., "sign in with Google"), which I have used in the past. And then they opened up Google's Authenticator app, signed in as me, and got the auth code for Coinbase.

By enabling cloud-sync, Google has created a massive security vulnerability for the entire industry. A developer can't be certain that auth codes are a true 2nd factor, if the account email is @gmail.com for a given user because that user might be using Google's Authenticator app.

davidscoville··on Scammed out of $130K via fake Google call, spoofed Google email and auth sync
That's the big question. I've heard attackers have used Google's own tools like Google forms or Google cloud to send the email through Google's servers so it wasn't flagged. This is a major vulnerability that Google needs to fix. I'm quitting Google because I'm worried about other vulnerabilities like this.
davidscoville··on Scammed out of $130K via fake Google call, spoofed Google email and auth sync
I updated the post and include the headers & html of the bounced-copy, although I don't think it's very useful.
davidscoville··on Scammed out of $130K via fake Google call, spoofed Google email and auth sync
I think the attacker had my password, and they just needed a recovery method, which was the code I read over the phone.

I have no idea how they had my password, I never share passwords or use the same password. But I hadn’t changed my Google password in a while.

davidscoville··on Scammed out of $130K via fake Google call, spoofed Google email and auth sync
I lost the original email—the attacker deleted all evidence and then cleared my trash (and yes I tried using the Google tool to find deleted emails, but the attacker cleared that too). The reason I have this email is because I forwarded this email on to phishing@google.com, before the attacker deleted everything. When I got control of my account, and removed the scammer recovery methods (he added a windows device—I don’t use windows, and a Brazil phone number), the email bounced back from phishing@google.com (apparently Google doesn’t accept that address). So what I have is the bounced-back copy.
davidscoville··on Scammed out of $130K via fake Google call, spoofed Google email and auth sync
The code I read to them was a Google account recovery code. That’s how they accessed my Google account. I, mistakenly, believed they needed to confirm I was still alive and the rightful owner of the account.

Then the attacker used Google SSO to perform the initial log in to my coinbase account. Then they opened Google Authenticator, signed in as me, to get the coinbase auth code so they could complete coinbase’s 2fac.

davidscoville··on Scammed out of $130K via fake Google call, spoofed Google email and auth sync
Exactly. Google created vulnerabilities for the whole industry by introducing cloud synced Authenticator codes.
davidscoville··on Scammed out of $130K via fake Google call, spoofed Google email and auth sync
I’ve heard scammers use Google tools like Google forms or Google cloud to send out fraudulent emails that appear like they come from Google.
davidscoville··on Scammed out of $130K via fake Google call, spoofed Google email and auth sync
I believe they logged into coinbase with Google SSO. And then they used my Google Authenticator codes which were cloud synced as the second factor auth method.

A warning to auth engineers: if an account is using a Gmail address, then auth codes from Google Authenticator should not be considered a second factor.