logoalt Hacker News

mattbisyesterday at 4:02 PM1 replyview on HN

You are probably right... I tend to change my password semi often. It's always a super complex impossible to remember string - and always keep an eye on the account activity.

Not to mention ; you would assume he should have more than one device linked to the account and then that adds another layer, since Google will ask you " is this you trying to logon ". <-- that is the only way to get Google to do the unrecognized flow you mention.

If you are suggesting it was exposed and he didn't immediately randomise all his passwords.. WORDS FAIL ME

It's all security 101 the irony is immense...

if the US government / FBI need someone to give some talks on how to do security ...


Replies

ffsm8yesterday at 4:21 PM

Changing a password that's randomly generated is security theatre. It doesn't meaningfully improve security

Also it's entirely possible they only compromised a honeypot.

Considering their track record, that's actually more likely tbh

show 1 reply