惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Microsoft Security Blog
Microsoft Security Blog
Apple Machine Learning Research
Apple Machine Learning Research
美团技术团队
WordPress大学
WordPress大学
酷 壳 – CoolShell
酷 壳 – CoolShell
G
Google Developers Blog
阮一峰的网络日志
阮一峰的网络日志
The Cloudflare Blog
J
Java Code Geeks
Martin Fowler
Martin Fowler
M
MIT News - Artificial intelligence
IT之家
IT之家
博客园 - 三生石上(FineUI控件)
月光博客
月光博客
Google DeepMind News
Google DeepMind News
小众软件
小众软件
V
V2EX
Hugging Face - Blog
Hugging Face - Blog
爱范儿
爱范儿
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Jina AI
Jina AI
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
腾讯CDC
B
Blog

Lauren Weinstein's Blog

Big Tech’s Catastrophic Layoffs Frenzy – Lauren Weinstein's Blog The Rise of AI Slop on Google’s YouTube – Lauren Weinstein's Blog Why Google Search AI Overviews Are a “Misinformation Machine” – Lauren Weinstein's Blog Why Apple’s New “MacBook Neo” Has Stunned the Tech World – Lauren Weinstein's Blog When Data Centers Destroy Communities – Lauren Weinstein's Blog Why You Shouldn’t Use Google’s Chrome “Auto Browse” Agentic AI, or Any Other Agentic AI From Other Firms – Lauren Weinstein's Blog Why Proposed “Blocking Technologies” for 3D Printers Are a Terrible Idea – Lauren Weinstein's Blog Cheerful, Cooperative, and Usually, Wrong. – Lauren Weinstein's Blog The World Gets an Important New Drone That Can Save Lives — But Thanks to Our Politicians Not in the USA – Lauren Weinstein's Blog Separating the Chrome Browser From Google Could Be Terrible for Billions of Users – Lauren Weinstein's Blog In the War Between the Federal Government and States Against Drone Maker DJI, Americans Are at Risk – Lauren Weinstein's Blog The Website Age Verification Train Wreck – Lauren Weinstein's Blog How the U.S. Is Losing Its Lead in Technology and Science Research – Lauren Weinstein's Blog The Enormous Negative Impacts of the New Tariffs on the Technology Sector – Lauren Weinstein's Blog DOGE Is Destroying Social Security, and Seniors Are Already at Risk – Lauren Weinstein's Blog Time To Change Section 230? – Lauren Weinstein's Blog The Helpful Google Ombudsman (Who Doesn’t Exist) – Lauren Weinstein's Blog Commerce Department Proposes Yet Another Insane Chinese Drone Ban That Could Cost Lives – Lauren Weinstein's Blog AI Is Dooming Google, but Not in the Way Its CEO Believes – Lauren Weinstein's Blog [What say you, Spock?] My Proposed Terminology to Describe Bypassing Social Media Face ID Age Verification Systems – Lauren Weinstein's Blog Drone Hysteria and Bans Put Lives at Risk – Lauren Weinstein's Blog Australia’s Under-16 Social Media Ban Is Doomed – Lauren Weinstein's Blog DOJ’s Proposed Antitrust “Remedies” Against Google Would Be a Disaster – Lauren Weinstein's Blog Users have the most to lose – Lauren Weinstein's Blog “I Am the Very Model of a Google AI Overview” – Lauren Weinstein's Blog What Google Should Do About Their Search Generative AI Overview Answers – Lauren Weinstein's Blog Generative AI Is Being Rammed Down Our Throats – Lauren Weinstein's Blog Evil – Lauren Weinstein's Blog The Nightmare of Google Account Recovery Failures – Lauren Weinstein's Blog Google and Seniors – Lauren Weinstein's Blog
Google’s Inactive Account Policy and Phishing Attacks Con...
2023-11-18 · via Lauren Weinstein's Blog

As you may know, Google has recently begun a protocol to delete inactive Google accounts, with email notices going out to the account and recovery addresses in advance as a warning.

Leaving aside for the moment the issue that so many people who have lost track of accounts probably have no recovery address specified (or an old one that no longer reaches them), there’s another serious problem.

A few days ago I received a legitimate Google email about an older Google account of mine that I haven’t used in some time. I was able to quickly reauthenticate it and bring it back to active status.

However, this may be the first situation (there may be earlier ones, but I can’t think of any offhand) where Google is actively “out of the blue” soliciting people to log into their accounts (and typically, older accounts that I suspect are more likely not to have 2-factor authentication enabled, for example).

This is creating an ideal template for phishing attacks.

We’ve long strongly urged users not to respond to emailed efforts to get them to provide their login credentials when they have not taken any specific actions that would trigger the need for logging in again — and of course this is a very common phishing technique (“You need to verify your account — click here.” “Your password is expiring — click here.”, etc.)

Unfortunately, this is essentially the form of the Google “reactivate your account” email notice. And for ordinary busy users who may get confused to see one of these pop into their inbox suddenly, they may either ignore them thinking that they are a phishing attack (and so ultimately lose their account and data), or may fall victim to similar appearing phishes leveraging the fact that Google is now sending these out.

I’ve already seen such a phish, claiming to be Google prompting with a link for a login to a supposedly inactive account. So this scenario is already occurring. The format looked good, and it was forged to appear to be from the same Google address as used for the legitimate Google inactive account notification emails.  Even the internal headers had been forged to make it appear to be from  Google. The top level “Received from” header line IP address was wrong of course, but how many people would notice this or even look at the headers to see this in the first place?

I can think of some ways to help mitigate these risks, but as this stands right now I am definitely very concerned. 

–Lauren–