Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Need to secure my Google account.


  • Please log in to reply
8 replies to this topic

#1 SuperSapien64

SuperSapien64

  • Members
  • 888 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:04 AM

Posted 21 March 2018 - 07:23 PM

My Google account got hacked again (fortunately Google automatically blocked it) and I don't think its malware because one I got a new phone and I didn't transfer over my installed apps with the Samsung Smart Switch Mobile and when I copied the contents from my old SD card to my new one I'm 99% positive I didn't copy over the Android folder. Two if I had any type spyware you think my social media app would've been hacked as well.

So I have some questions about securing my Google account.

If I use two step verification will I be able to use my Gmail account with Mozilla Thunderbird or K9 Mail?

Do you think I should turn off less secure app access?



BC AdBot (Login to Remove)

 


#2 britechguy

britechguy

    Been there, done that, got the T-shirt


  • Moderator
  • 7,818 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Staunton, VA
  • Local time:10:04 AM

Posted 21 March 2018 - 09:40 PM

If Google blocked the attempted intrusion then saying "I was hacked" is inaccurate.

 

It is not unusual to have the occasional attempt to access an account by an unauthorized individual.  If that attempt is blocked you weren't hacked, or anything close to it.  The existing security worked.

 

I get the occasional once in a blue moon Google warning about someone/something attempting to access my account and it wasn't me.  If it's the occasional one-off then I don't get worked up about it.

 

If the message indicates the account was actually accessed then follow the instructions given by Google for securing your account.


Brian  AKA  Bri the Tech Guy (website in my user profile) - Windows 10 Home, 64-Bit, Version 1803, Build 17134 

      Memory is a crazy woman that hoards rags and throws away food.

                    ~ Austin O'Malley

 

 

 

              

 


#3 STS-1

STS-1

  • Members
  • 65 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:04 AM

Posted 22 March 2018 - 01:03 AM

When you use a 3rd party program with Google 2 step verification, you will get a prompt that allows you to give access to the 3rd party app, which then "locks in" the 2 step verification code that you use when setting up, just remember to remove the permission from your google account if you ever stop using that 3rd party app!



#4 SuperSapien64

SuperSapien64
  • Topic Starter

  • Members
  • 888 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:04 AM

Posted 22 March 2018 - 02:54 PM

If Google blocked the attempted intrusion then saying "I was hacked" is inaccurate.

 

It is not unusual to have the occasional attempt to access an account by an unauthorized individual.  If that attempt is blocked you weren't hacked, or anything close to it.  The existing security worked.

 

I get the occasional once in a blue moon Google warning about someone/something attempting to access my account and it wasn't me.  If it's the occasional one-off then I don't get worked up about it.

 

If the message indicates the account was actually accessed then follow the instructions given by Google for securing your account.

Well in the past about a year ago they managed to access my account multiple times but I would block them every time shortly after they accessed my account. So Google must of recognized that this hack attempt is from a unknown device so every time that unknown device tries to login to my account Google blocks it.

But if this isn't malware how are they hacking my account? I mean I have a random 18+ character password.



#5 britechguy

britechguy

    Been there, done that, got the T-shirt


  • Moderator
  • 7,818 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Staunton, VA
  • Local time:10:04 AM

Posted 22 March 2018 - 03:41 PM

If you yourself try to log in to your Google account using your own laptop in a coffeeshop or hotel, for instance, that's several states away from where you typically use that laptop to log in you will get "unknown device" warnings and be asked to verify your account by supplying either your backup e-mail or phone number that you gave to Google.  That's after you've already provided the correct password.  Even if you can do that you will get e-mail messages very shortly afterward from Google asking you to confirm it was indeed you.

 

I don't know what you're using to make the statement, "they managed to access my account multiple times," because Google has had the system it uses in place for several years now.  It is common practice to collect e-mail addresses and then to send out spam using those e-mail addresses as spoofing addresses.

 

You need to be a lot more specific in what you mean by "hacked."  An attempt to access your account isn't hacking, though it could be an attempt at hacking.  It could also be someone with the account that is one character off yours fat-fingering their account name at login and making multiple attempts before realizing their mistake.


Brian  AKA  Bri the Tech Guy (website in my user profile) - Windows 10 Home, 64-Bit, Version 1803, Build 17134 

      Memory is a crazy woman that hoards rags and throws away food.

                    ~ Austin O'Malley

 

 

 

              

 


#6 SuperSapien64

SuperSapien64
  • Topic Starter

  • Members
  • 888 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:04 AM

Posted 22 March 2018 - 08:16 PM

@ britechguy

 

I don't ever use Public WiFi on my smartphone or laptop also I don't travel.

And I say they cause I don't know how many people are involved with the hack.

 

Quote: though it could be an attempt at hacking. Yes thats what it was and it happened ever 3 to 6 months for about a year and happened again but this time Google auto blocked the login.



#7 britechguy

britechguy

    Been there, done that, got the T-shirt


  • Moderator
  • 7,818 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Staunton, VA
  • Local time:10:04 AM

Posted 22 March 2018 - 08:25 PM

Again, and for the last time:  an attempt at access/hacking and actually being hacked are two entirely different things.

 

There is nothing that you have offered that would cause me concern, period, if they are isolated incidents happening infrequently.


Brian  AKA  Bri the Tech Guy (website in my user profile) - Windows 10 Home, 64-Bit, Version 1803, Build 17134 

      Memory is a crazy woman that hoards rags and throws away food.

                    ~ Austin O'Malley

 

 

 

              

 


#8 MarkMackerel

MarkMackerel

  • Malware Study Hall Sophomore
  • 76 posts
  • OFFLINE
  •  
  • Local time:03:04 PM

Posted 23 March 2018 - 02:16 AM

Turn on 2 factor authentication and make sure you have to use your your phone in conjunction with any log in. That way nobody can log in to your account without tapping on the prompt that comes up on your phone.

 

One thing worth keeping in mind though is that according to Edward Snowden leaks, the NSA had access to gmail accounts. 



#9 SuperSapien64

SuperSapien64
  • Topic Starter

  • Members
  • 888 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:04 AM

Posted 25 March 2018 - 08:52 PM

Turn on 2 factor authentication and make sure you have to use your your phone in conjunction with any log in. That way nobody can log in to your account without tapping on the prompt that comes up on your phone.

 

One thing worth keeping in mind though is that according to Edward Snowden leaks, the NSA had access to gmail accounts. 

If I do that I'll probably have to Sign in using App Passwords: https://support.google.com/mail/answer/185833?rd=1&visit_id=1-636392160493875275-2904245789

for K9 Mail and other apps.






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users