Hackers discover way to access Google accounts without a password::‘Exploit enables continuous access to Google services, even after a user’s password is reset,’ researcher warns

  • hperrin@lemmy.world
    link
    fedilink
    English
    arrow-up
    67
    arrow-down
    5
    ·
    edit-2
    2 years ago

    This isn’t new at all. This is called session hijacking, and it’s been around for decades.

    LTT just made a couple videos about it last year, because it happened to them.

    • Buck@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      2 years ago

      I was able to bypass that by logging into YouTube without a phone number, and then going to Google accounts. Not sure if that still works.

    • Cornelius_Wangenheim@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      ·
      edit-2
      2 years ago

      The main difference that makes this worse is that they can get persistence and maintain access even if the user resets their password (i.e. revoke session tokens). Hackers are usually limited to the fairly short lifetime of the session token (usually a few hours).