|
@svblxyz | |||||
|
TIL you can leak the device name with attempted pw reset of a Gmail account. twitter.com/akolsuoicauqol…
|
||||||
|
||||||
|
Royce Williams
@TychoTithonus
|
2. sij |
|
What is the workflow to get to this particular dialog? I've run through a few Gmail accounts and can't get this result - only masked email addresses.
|
||
|
|
||
|
pry0cc
@pry0cc
|
2. sij |
|
“Try another way” and be in the same geographical location as the account
|
||
|
|
||
|
Adrian Rueegsegger
@Kensan42
|
3. sij |
|
Namespace compromise. /cc @pvineetha
|
||
|
|
||
|
✨ Lizard Queen (Pronouns: TRH-TheirRoyalHighness)✨
@pvineetha
|
3. sij |
|
Yup, saw this... FWIW this was one of the gmail password reset compromise things I was discussing with @generativist over the summer. We were discussing him sending me a follow up email about his experience but meanwhile I got other sources in the wild such as this one.
|
||
|
|
||
|
David Anson
@DavidAns
|
2. sij |
|
Which wouldn’t be as much of a concern if your device name was meaningless.
|
||
|
|
||
|
OSINT
@AccessOSINT
|
2. sij |
|
Sometimes there is even a drop down and you can see multiple phones if they have more than one connected. And to the others in this thread, being close geographically is the first time I am hearing about it. I have seen this on US accounts and I am in the UK.
|
||
|
|
||
|
Super1337Johanssonson
@malwrandpickles
|
3. sij |
|
Always knew of this technique, but unsure about the legal implications, if any when doing so. Maybe someone who knows the law could chime in. For future reference and such.
|
||
|
|
||