Hackers discover way to access Google accounts without a password::‘Exploit enables continuous access to Google services, even after a user’s password is reset,’ researcher warns
This isn’t new at all. This is called session hijacking, and it’s been around for decades.
LTT just made a couple videos about it last year, because it happened to them.
deleted by creator
If you’re in California or the EU you could always just tell them to delete it anyway.
I was able to bypass that by logging into YouTube without a phone number, and then going to Google accounts. Not sure if that still works.
Firefox users keep winning.
Firefox isn’t magically immune to session hijacking…
So the moral is use Firefox and not Chrome?!
So it is session hijacking, something that has been known for a while?
The main difference that makes this worse is that they can get persistence and maintain access even if the user resets their password (i.e. revoke session tokens). Hackers are usually limited to the fairly short lifetime of the session token (usually a few hours).