←back to thread

193 points todsacerdoti | 1 comments | | HN request time: 0s | source
Show context
alchemist1e9 ◴[] No.41084731[source]
This was done to me. They even called me imitating google security team by using google assistant feature and using a free trial to register my own phone number as the business name then calling via Google to get assistant to call me repeatedly showing up as google. Eventually I picked up as I was also get simultaneously account recovery requests on my gmail. AND they sent me DKIM verified emails that appear to come from google themselves. I recorded the phone conversation if LE might be interested. The combination of there existing an account on workspaces, verified emails, and spoofed google caller ID from numbers that superficially appear to be actually google numbers - you have to read closely that they are Google Assistant numbers! was pretty convincing initially, they had be for a few minutes on the call. And they tell you your account is having it’s phone number changed, we need to do something now or it will take a long time to recover it. I didn’t fall for it but then I pretended I was and put on a big show. I have a long recording with their voice and timestamps of everything.

Anyway the incident shook me as they also gave me my personal information to prove they are real and it was accurate and kept saying look we aren’t asking you for information we are telling you yours so you see we are Google Security!

It has triggered for me a giant project to carefully review all my attack surfaces across all accounts and systems.

replies(2): >>41085063 #>>41096079 #
thebruce87m ◴[] No.41096079[source]
My alarm bells would be going off for one reason only:

Support at google is non-existent. You would never get them proactively calling you about anything. Hell, phoning them and ending up with a human would be a miracle.

replies(1): >>41105878 #
1. alchemist1e9 ◴[] No.41105878[source]
Yeah I found that out trying to report my attempt. It’s impossible to talk to a human. It was very dystopian.

I’ve been thinking afterwords what is actually the most resilient to attack digital identity strategy. Does it actually maybe mean owning your own domain and keeping it with a registrar with heavy authentication procedures and then running your own email services? It’s a huge amount of work and even then do you cloud host and then that’s a weakness. Maybe my email address should have 2FA for both sending and receiving messages, does that even exist in some IMAP extension protocol and some obscure email client.

It all sounds crazy yet if you don’t want to risk Google deciding to erase you or let somebody else take over your primary email address then maybe it’s the only possible option for an advanced threat target.