New issue
Advanced search Search tips

Issue 614798 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: May 2016
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug-Security



Sign in to add a comment

ability to change gmail password in 5 minutes without answering security questions

Reported by gbcelect...@gmail.com, May 25 2016

Issue description

UserAgent: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36

Steps to reproduce the problem:
1. I am a teacher in Canada and discovered that our shared google drive had been compromised. Within a few minutes of watching this video https://www.youtube.com/watch?v=pUwxNGWy1PQ I was able to change the password to our staff google account and gain access to all the teachers files on the google drive that was associated with gbcelectrical@gmail.com
This is unacceptable, I didn't have to answer any security questions, I merely had to enter the last date that the gmail account had been opened. Please inform me when this has been rectified as we can no longer use your google drive as a secure area to store shared documents. 

Regards, 

Peter Vree
416-575-7634
vree.peter@gmail.com
2. 
3. 

What is the expected behavior?

What went wrong?
I am a teacher in Canada and discovered that our shared google drive had been compromised. Within a few minutes of watching this video https://www.youtube.com/watch?v=pUwxNGWy1PQ I was able to change the password to our staff google account and gain access to all the teachers files on the google drive that was associated with gbcelectrical@gmail.com
This is unacceptable, I didn't have to answer any security questions, I merely had to enter the last date that the gmail account had been opened. Please inform me when this has been rectified as we can no longer use your google drive as a secure area to store shared documents. 

Regards, 

Peter Vree
416-575-7634
vree.peter@gmail.com

Did this work before? N/A 

Chrome version: 50.0.2661.102  Channel: n/a
OS Version: 10.0
Flash Version: Shockwave Flash 21.0 r0
 

Comment 1 by mea...@chromium.org, May 25 2016

Status: WontFix (was: Unconfirmed)
Thanks for the report.

The process in the video you linked requires the recovery email to be associated with the recovered email beforehand. In your case, you probably already had a recovery address registered for gbcelectrical@gmail.com. Doing that would require access to gbcelectrical@gmail.com in the first place. As such, I don't see a vulnerability here, the process seems to work as intended. 

Note that Google doesn't use security questions anymore, as they are not really secure. You'll see a similar message on the page at  https://security.google.com/settings/security/signinoptions/securityquestion
Project Member

Comment 2 by sheriffbot@chromium.org, Sep 1 2016

Labels: -Restrict-View-SecurityTeam
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 3 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 4 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic

Sign in to add a comment