TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Google hacked account

203 点作者 hmoghnie将近 10 年前
Despite Google boasting of hiring the best engineers. Their system give us mortals hope that our applications are not so bad after all. Let me explain the pain I am going through to recover my hacked gmail account. First, there is no way to talk to someone, their responses are canned, and to top it off, they send you to a link to submit a password request.<p>So far not a problem, but the email you get back after sending the password reset request contains a link to a page that allows you to cancel the request (not sure the genius who had this idea). Now that the email is hacked, the hacker can read the emails and click to cancel the recovery process. And the vicious cycle continues.<p>What to do?

39 条评论

andybak将近 10 年前
Try posting to Hacker News in the hope someone with some authority deigns to intervene. It helps if you a high-profile blogger or known industry luminary.<p>The prospects for the rest of us are fairly bleak.
评论 #9805083 未加载
评论 #9804447 未加载
评论 #9805024 未加载
sombremesa将近 10 年前
If they are automatically clicking these links you may be able to spoof an E-mail that looks similar to the password reset request but have the cancel link actually log them out.<p>Going to this URL logs you out on Gmail: <a href="https:&#x2F;&#x2F;accounts.google.com&#x2F;Logout?service=mail&amp;continue=https:&#x2F;&#x2F;mail.google.com&#x2F;mail&amp;hl=en" rel="nofollow">https:&#x2F;&#x2F;accounts.google.com&#x2F;Logout?service=mail&amp;continue=htt...</a><p>This might not work, but it&#x27;s probably worth a try.
评论 #9805472 未加载
w8rbt将近 10 年前
If your account is part of Google Apps for Education, or some other managed Google Apps account, you should contact your Google Apps admin. If it&#x27;s just a normal Google account, I&#x27;m not sure there&#x27;s much more that you can do.<p>Email is the most sought after account. All the password reset requests to your Bank, Twitter, Facebook, etc. are delivered to your email account. So when someone steals your email account, they&#x27;ve stolen all the others too. Go change those accounts to use your new email (if you can).
评论 #9804592 未加载
jmilloy将近 10 年前
I agree that Google&#x27;s help services are lacking. I never got my account back years ago. But this sounds fishy to me.<p>It&#x27;s equally likely that you are trying to <i>hack</i> someone else&#x27;s account as trying to recover your own. There&#x27;s nothing wrong with the password reset process.<p>However, isn&#x27;t there a process for when you suspect your account has been compromised? Have you even tried that? Are you even sure that your account has been compromised, or you just can&#x27;t remember your password?<p>I like that us hackers are happy to help, and happy to commiserate with the failings of big corporations, but I think it&#x27;s worthwhile to be a bit sceptical.<p>Edit: I&#x27;ll add that the claim that the reset requests are going to the original account and being cancelled is fishy. We have verification in this thread that this in fact does <i>not</i> happen, and presumably the OP can&#x27;t access the account to make a truthful counter claim.
finnjohnsen2将近 10 年前
You had two step verification, or not?<p>I&#x27;m hoping you&#x27;ll say no, because my feeling of security comes from the fact I&#x27;ve enabled TSV.
评论 #9804956 未加载
评论 #9804994 未加载
评论 #9804595 未加载
yandie将近 10 年前
&gt; So far not a problem, but the email you get back after sending the password reset request contains a link to a page that allows you to cancel the request (not sure the genius who had this idea)<p>Did you set the recovery email the same as the main email? Cause I only get password reset to the recovery email.<p>If you used the same address for recovery email, then it defeats the whole purpose
评论 #9804725 未加载
heavymark将近 10 年前
Would be interested in knowing how they bypassed 2 factor authentication, assuming you had that enabled.<p>Unfortunately, it&#x27;s a tough situation since for all Google or we know you could be the hacker trying to get into the account and hard for them to verify who you are, since if the hacker was able to steal person&#x27;s phone to bypass 2 factor authentication, they may also have access to a copy of your drivers license or ID to send to google in an attempt to verify they are you.<p>While far from ideal, assuming you don&#x27;t have a close friend to contact google for you via their google apps admin account, you could create a new trial google admin account and then contact google through that mentioning your situation of your other account. While they will still have to find a way to verify who you are at least you&#x27;ll reach a real person.
评论 #9804499 未加载
评论 #9804708 未加载
评论 #9804515 未加载
FredericJ将近 10 年前
The issue is that you&#x27;re not Google&#x27;s client. Maybe buy something from them (a large amount of ads), then try to get support?
评论 #9804677 未加载
评论 #9805052 未加载
评论 #9804591 未加载
itsbits将近 10 年前
Someone hacked and deleted my gmail account back in 2008. And I wasn&#x27;t able to create another with same name. It was like my life that time coz I had all my personal backups as mails in that one. Since then I keep a copy in my harddrive as well even when I have cloud account.
y0ghur7_xxx将近 10 年前
Unfortunately (because their services are quite good) google has no support staff. This is well known, and you should take it into account when using the services they offer.<p>It is not difficult to do without them.<p>Asking for help on HN or Reddit works sometimes, but if your business (or personal life for that matter) relies on their services you should really work towards being able to do without them.
评论 #9804642 未加载
评论 #9804644 未加载
philbo将近 10 年前
This actually happened to me a few years back and, eventually, they were very helpful.<p>The key for me was providing sufficient proof that the account really was mine and really had been hacked. I gave them as much information as I could remember&#x2F;check:<p>* some contact names<p>* some tag names<p>* some recent thread subjects&#x2F;recipients<p>* name of the person who first invited me to GMail back in the day<p>* details of any labs settings, theme etc<p>* mailing list subscriptions<p>I wish I could remember the email address I used to get in touch with them but, as I said, this was years ago now. I definitely found it somewhere publicly available, albeit buried somewhat.<p>HTH
topynate将近 10 年前
Hm, I&#x27;d try timing the request so that it&#x27;s the middle of the night wherever the thief lives. Try once assuming that he lives in America, once assuming Eastern Europe.
评论 #9804634 未加载
评论 #9804767 未加载
creyer将近 10 年前
I guess is all about: how can you prove you&#x27;re not the hacker?
评论 #9804842 未加载
评论 #9805959 未加载
EGreg将近 10 年前
The right way for these companies to restore your account would be several of the contacts you&#x27;ve added long ago to verify that it is indeed you, in some way a machine can use, such as you signing in with your OLD credentials (which are kept around), filling out a form with their contact details (which were in the addressbook on the service and to which you have sent at least a few emails long ago) and them forwarding you the generated keys to your email by some method they choose to reach you -- only by collecting 4 or 5 of these keys could anyone unlock the account. Presumably you choose the people to whom you&#x27;ve reached out another way and explained how to tell you the code to activate your email.<p>This is like an alternative to two-factor communication. It can only be defeated by someone actually hacking your account and then convincing 3-4 of your close friends to send him the keys to your account when you start the dispute.<p>I&#x27;m a big fan of using information obtained easily and casually in the course of doing something productive (like often emailing someone) for good purposes.<p>PS: I have disclosed it publicly on this date so no patenting! :-)
mark_l_watson将近 10 年前
Google provides some great services, but support is lacking.<p>I suggest, for the future: 1) use two factor authorization 2) use a separate email service because email is so important that you need the best support, etc. that you can get (I use Fastmail) 3) periodically download your Google data so if you ever need to set up a new Google account, you have some of your old context<p>I do still use GMail, but as a backup email.<p>I am going to start teaching free Internet security and privacy classes at my local library so I have been thinking a lot about these issues. Google, Facebook, Twitter, etc. provide really nice services, but it is important to consider privacy issues and have a plan for using these &quot;free&quot; services.
q3k将近 10 年前
It&#x27;s a free service. You get what you pay for.
评论 #9804739 未加载
brightball将近 10 年前
If they&#x27;re going to have cancel password change requests they also have to have cancel change of alternative email requests. That&#x27;s the first thing a hacker changes.<p>Additionally, you have to track every change with a timestamp so that you can invalid everything that came AFTER the change you just reset. That will prevent a hacker from being able to screw with the account because the original email address will also be able to cancel future changes, no matter how many times the perpetrator did it.
aseemraj将近 10 年前
Google sends the recovery information related emails on the recovery email address. So they won&#x27;t be going to the account that is not accessible to you (I prefer to say that instead of hacked). And the link to cancel the request is indeed a good idea, because if someone else submits a password reset request, then you must be able to cancel it because you did not initiate it. Otherwise, you will end up losing your account to the real initiator of the request.
ruanmartinelli将近 10 年前
Adding to discussion: once I tried changing a corworker&#x27;s gmail password just for fun (he was right beside me and doubted that I could) by just providing few ordinary information I knew about him (e-mail lists we were both subscribed to, e-mail from our boss, other coworkers, etc). Well, I was able to change his password to a completely new one. Very concerning, not sure if it still remains that easy.
hellbanner将近 10 年前
A while back, I was chatting with someone on gTalk who I had pissed off in a forum. The next time I tried to sign in, my password has changed. I had to do the reset.. when I signed back in, no signs of foreign IP access was there.<p>My best guess: malware on the forum OR they exploited a vuln on Gmail.com similar to how hotmail.com &amp; yahoo.com used to be very very vulnerable..
frosttt将近 10 年前
You can try here. <a href="https:&#x2F;&#x2F;productforums.google.com&#x2F;forum&#x2F;#!forum&#x2F;gmail" rel="nofollow">https:&#x2F;&#x2F;productforums.google.com&#x2F;forum&#x2F;#!forum&#x2F;gmail</a>
hiou将近 10 年前
I would see if you can upgrade your gmail to a paid account and then contact their support. Free accounts get very little attention but paid accounts will get you to a real person eventually.
评论 #9805471 未加载
rghose将近 10 年前
I guess you just need to be faster than the person who hacked your account. Just before the cancel link is clicked you gotta make your move.<p>Yeah, and the cancel request was a total stroke of genius!
评论 #9805100 未加载
BtM909将近 10 年前
I&#x27;m assuming you&#x27;ve tried this: <a href="https:&#x2F;&#x2F;support.google.com&#x2F;mail&#x2F;answer&#x2F;50270?hl=en&amp;ref_topic=3406179" rel="nofollow">https:&#x2F;&#x2F;support.google.com&#x2F;mail&#x2F;answer&#x2F;50270?hl=en&amp;ref_topic...</a>.<p>On the other hand, it is a free service. If you&#x27;d have the business subscription, they do have a helpdesk you can contact by phone: <a href="https:&#x2F;&#x2F;www.google.com&#x2F;work&#x2F;apps&#x2F;business&#x2F;support&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.google.com&#x2F;work&#x2F;apps&#x2F;business&#x2F;support&#x2F;</a>
评论 #9804367 未加载
评论 #9804444 未加载
black-perl将近 10 年前
And, the loop continues. Can&#x27;t they reset your gmail account. Yes they can ! Ask them explaining the problem.
resulemniyet将近 10 年前
<a href="https:&#x2F;&#x2F;www.emniyetevdenevenakliyat.com" rel="nofollow">https:&#x2F;&#x2F;www.emniyetevdenevenakliyat.com</a> <a href="https:&#x2F;&#x2F;www.kayserievdeneve-nakliyat.com" rel="nofollow">https:&#x2F;&#x2F;www.kayserievdeneve-nakliyat.com</a> <a href="https:&#x2F;&#x2F;www.kayserievdenevenakliyeciler.net" rel="nofollow">https:&#x2F;&#x2F;www.kayserievdenevenakliyeciler.net</a> <a href="https:&#x2F;&#x2F;www.kayseri-evdenevenakliyat.net" rel="nofollow">https:&#x2F;&#x2F;www.kayseri-evdenevenakliyat.net</a> Eşyalarınızın büyük olması asansörlü taşınma için engel teşkil etmez.Binanız pimapen pencere olduğu müddetçe eşya büyüklüğü önemsiz kalır.Çünkü pimapen pencereleri tamamen söküyoruz. Bir şehirden öteki bir şehre nakliyat işleriniz olduğunda size nakliyat için bir zaman veririz ve bu süre içinde nakliyat işleriniz tamamlanmış olur. şehirler arası taşımacılıkta kayseri evden eve Nakliyat kalitesini yaşamak için çok sayıda seçeneğiniz var. Taşınacak eşyanın cinsi büyüklüğü ne olursa olsun Türkiye’nin bütün illerine hizmet vermekteyiz… Eşya taşıttırmak isteyen müşterilerimize sunduğumuz hizmetler arasında asansörlü eşya taşımacılığı yanı sıra anahtar teslim evden eve taşımada sunuyoruz. Firmamız kayseri melikgazi de ofisimiz kayseri ve tum turkiye evden eve nakliyat bizim işimiz Asansörlü kayseri evden eve nakliyat hizmeti şimdilerde moda olup en iyi ve kaliteli taşınma için mükemmel çözüm.Kayseri evden eve nakliyat firma elemanları olarak hizmet veren arkadaşlarımız asansör ile yapılan işlerin daha kaliteli ve güvenilir olduğunu bizimle paylaştıktan sonra artık işlerimi bu kalitede olacaktır. <a href="https:&#x2F;&#x2F;www.nevsehirevdenevenakliye.com" rel="nofollow">https:&#x2F;&#x2F;www.nevsehirevdenevenakliye.com</a> <a href="https:&#x2F;&#x2F;www.aksarayevdenevenakliyat.biz" rel="nofollow">https:&#x2F;&#x2F;www.aksarayevdenevenakliyat.biz</a> <a href="https:&#x2F;&#x2F;www.evdenevenakliyatc.net" rel="nofollow">https:&#x2F;&#x2F;www.evdenevenakliyatc.net</a> <a href="https:&#x2F;&#x2F;www.kayserievdenevenakliyat.biz" rel="nofollow">https:&#x2F;&#x2F;www.kayserievdenevenakliyat.biz</a> <a href="https:&#x2F;&#x2F;www.hizmetevdeneve.com" rel="nofollow">https:&#x2F;&#x2F;www.hizmetevdeneve.com</a> <a href="https:&#x2F;&#x2F;www.kayserievdenevenakliye.net" rel="nofollow">https:&#x2F;&#x2F;www.kayserievdenevenakliye.net</a> <a href="http:&#x2F;&#x2F;nigdeevdeneve-nakliyat.com&#x2F;" rel="nofollow">http:&#x2F;&#x2F;nigdeevdeneve-nakliyat.com&#x2F;</a> <a href="https:&#x2F;&#x2F;www.sivasevdenevenakliyat.biz" rel="nofollow">https:&#x2F;&#x2F;www.sivasevdenevenakliyat.biz</a> <a href="https:&#x2F;&#x2F;www.yozgatevdeneve-nakliyat.com" rel="nofollow">https:&#x2F;&#x2F;www.yozgatevdeneve-nakliyat.com</a> <a href="http:&#x2F;&#x2F;www.evdenevenakliyatciler.net&#x2F;" rel="nofollow">http:&#x2F;&#x2F;www.evdenevenakliyatciler.net&#x2F;</a>
bingobob将近 10 年前
if you get your account back i would look at setting up 2-Step Verification <a href="https:&#x2F;&#x2F;support.google.com&#x2F;accounts&#x2F;answer&#x2F;180744?hl=en" rel="nofollow">https:&#x2F;&#x2F;support.google.com&#x2F;accounts&#x2F;answer&#x2F;180744?hl=en</a>
frosttt将近 10 年前
Have you tried the forums? If so, could you point me to the post, please?
cbaleanu将近 10 年前
You can also receive a pin code via sms on your phone...
评论 #9804365 未加载
cmdrfred将近 10 年前
Hacker != Guy who phished your password
评论 #9806551 未加载
timruffles将近 10 年前
For next time: pay for google apps.
frosttt将近 10 年前
Did you post on the gmail forums?
评论 #9805160 未加载
9931323781将近 10 年前
MY AIM IS ALL INDIA RANK 1st in IIT JEE AND IChallange 95%MARKS IN BIHAR BOARD EXAMINTION IN 2016
chintan将近 10 年前
edge case - scheduled for sprint # 5642
pooooooop90900将近 10 年前
Cool
kazinator将近 10 年前
&gt; <i>What to do?</i><p>The first step would be to edit the title of your submission to begin with &quot;Ask HN: hacked Google account, what to do?&quot;, since you&#x27;re asking a question.<p>&quot;Google hacked account&quot; means, to an English speaker, that Google perpetrated hacking against some account somewhere (subject-verb-object, right?) E.g. Google people gained access to your bank account. I.e. your current submission title is clickbait.
评论 #9805033 未加载
评论 #9805136 未加载
评论 #9804962 未加载
9931323781将近 10 年前
I WANT TO CHAIRMAN OF GOOGLE
Adiminstrator将近 10 年前
Hello,<p>I believe i can help.
评论 #9804824 未加载
praalka将近 10 年前
they went full microsoft
评论 #9804942 未加载
评论 #9805332 未加载