Hacks and Incidents

Bypassing Google’s Two-Factor Authentication

Bypassing Google’s Two-Factor Authentication: Some months ago, we found a way to (ab)use ASPs to gain full control over Google accounts, completely circumventing Google’s 2-step verification process. We communicated our findings to Google’s security team, and recently heard back from them that they had implemented some changes to mitigate the most serious of the threats we’d uncovered.