Security: Find My Device DEAD END
Reported by
monpronu...@gmail.com,
Jan 30 2018
|
||||||
Issue descriptionVULNERABILITY DETAILS I found a dead end on the find my device, while i was testing out my new phone. The process that I went through came to a dead end which will result the user to not find their device. I believe this is a legitimate problem and I want to know if this would qualify to the Rewards Program and how much would be the reward if ever it is one.
,
Jan 30 2018
This doesn't sound like a security issue. Removing the security label. monpronuevo@gmail.com please note this bug is now publicly visible so please avoid publishing any sensitive information.
,
Jan 30 2018
I was trying to find my new phone via google search. "find my device" then it asked me to sign in then i have a two verification step which is the dead end. I can fully explain with screenshots.
,
Jan 30 2018
Thank you for providing more feedback. Adding requester "raymes@chromium.org" to the cc list and removing "Needs-Feedback" label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Jan 30 2018
Please do post screenshots.
,
Jan 31 2018
I attached it here and I uploaded it as well on this site: https://i.imgur.com/lcrOTq3.jpg Follow these steps while looking at the screenshot. 1. Type find my device on google search. Its gonna ask you to sign in again on your gmail. 2. Sign in with your gmail. 3. Now here comes the tricky part. Since I have a 2-step verification on, its asking me to send a text message on my phone. Which would be very impossible to do since I don't have my phone with me, right now its "lost". 4. I tried the "more options" There's only 2 option which is the same thing. 5. On the same screen i tried to get help. 6. This is where the dead end is. There's no other way, which is to request Google's help which directs me in trying to recover my gmail account which I do not need because I did not lost my account login.
,
Jan 31 2018
Thank you for providing more feedback. Adding requester "raymes@chromium.org" to the cc list and removing "Needs-Feedback" label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Jan 31 2018
Thanks monpronuevo. Unfortunately, because you have 2-factor authentication turned on and because you have lost access to your phone, you will need to do a full account recovery by contacting Google: https://accounts.google.com/signin/recovery?hl=en. It isn't enough to have the username and password.
,
Jan 31 2018
@raymes That's the issue that i am telling you about, so let's say there will be half millions of people lost their phone in 1 day and they wanted to track it and half millions of them have 2-factor authentication turned on, do you want all of them to go through the full account recovery option.
,
Jan 31 2018
Re #9: Yes, when 2-Factor is enabled, by-design, 2-Factor is required. However, the Chrome bug tracker is not the appropriate venue for this discussion, as no one here works on the Google Accounts service and thus no one here can speak about it in any official capacity. |
||||||
►
Sign in to add a comment |
||||||
Comment 1 by elawrence@chromium.org
, Jan 30 2018