GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Rich Felker (dalias@hachyderm.io)'s status on Tuesday, 05-Nov-2024 01:29:26 JST Rich Felker Rich Felker

    Fucking Google put 2FA on my Gmail account without my consent and tried to force me to click a notification supposedly sent to Play Services on my phone (not a thing because it's microG not Play Services) to verify it's me logging in. 🤬

    In conversation about 7 months ago from hachyderm.io permalink
    • Embed this notice
      Rich Felker (dalias@hachyderm.io)'s status on Tuesday, 05-Nov-2024 01:30:13 JST Rich Felker Rich Felker
      in reply to

      If I didn't have another live browser session with ability to use the g.co/verifyaccount workflow instead, this would have been full account lockout. 🤬

      🖕 you Google

      In conversation about 7 months ago permalink

      Attachments

      1. No result found on File_thumbnail lookup.
        Account settings: Your browser is not supported.
    • Embed this notice
      Rich Felker (dalias@hachyderm.io)'s status on Tuesday, 05-Nov-2024 01:37:38 JST Rich Felker Rich Felker
      in reply to

      Browsing through Google Account settings, it looks like anything they think is a logged-in phone is automatically treated as a valid 2FA source for your account regardless of whether you wanted it to be.

      This is not just unwanted 2FA but a huge security violation. It means a lost or stolen phone logged into your account, or one a child is using, etc., can be used as a full account takeover vector.

      In conversation about 7 months ago permalink
    • Embed this notice
      Rich Felker (dalias@hachyderm.io)'s status on Tuesday, 05-Nov-2024 01:38:40 JST Rich Felker Rich Felker
      in reply to

      Probably time to delete the Gmail app and find third-party mail and chat client to use with my Gmail account instead so I can delete the account login from microG...

      In conversation about 7 months ago permalink
    • Embed this notice
      Rich Felker (dalias@hachyderm.io)'s status on Tuesday, 05-Nov-2024 01:40:33 JST Rich Felker Rich Felker
      in reply to

      Somehow they'd also gotten and added my phone number 😱 as an account recovery source, and the UI asking me to verify it made it seem like it was refusing to delete it, but then when I got to Account page, it showed "Recovery phone deleted" under recent activity. 🤦

      The clowns making this stuff have utterly no idea what they're doing, much less how they're fucking people over.

      In conversation about 7 months ago permalink
    • Embed this notice
      axleyjc (axleyjc@federate.social)'s status on Tuesday, 05-Nov-2024 03:36:26 JST axleyjc axleyjc
      in reply to

      @dalias I hate that they don't let you disable push to authenticate 2fa. Especially on kid accounts.

      In conversation about 7 months ago permalink
    • Embed this notice
      Rich Felker (dalias@hachyderm.io)'s status on Tuesday, 05-Nov-2024 03:37:10 JST Rich Felker Rich Felker
      in reply to
      • axleyjc

      @axleyjc Yes. Push to authenticate is an extremely dangerous account takeover vector. It should never even be an option much less impossible to disable.

      In conversation about 7 months ago permalink
    • Embed this notice
      Rich Felker (dalias@hachyderm.io)'s status on Tuesday, 05-Nov-2024 07:07:38 JST Rich Felker Rich Felker
      in reply to
      • axleyjc

      @axleyjc Yeah I've never turned on Advanced Protection. My password is in a vault and entered maybe once a year, probably more like once every five. I do not want any 2FA or alternative weak authentication vectors.

      In conversation about 7 months ago permalink
    • Embed this notice
      axleyjc (axleyjc@federate.social)'s status on Tuesday, 05-Nov-2024 07:07:39 JST axleyjc axleyjc
      in reply to

      @dalias Damn it! Just checked and advanced protection leaves that enabled. Ffs!

      In conversation about 7 months ago permalink
    • Embed this notice
      axleyjc (axleyjc@federate.social)'s status on Tuesday, 05-Nov-2024 07:07:40 JST axleyjc axleyjc
      in reply to

      @dalias I think the only way to disable that wfa is to enable Advanced Protection

      In conversation about 7 months ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.