New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 807434 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Jan 2018
Cc:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug



Sign in to add a comment

Security: Find My Device DEAD END

Reported by monpronu...@gmail.com, Jan 30 2018

Issue description

VULNERABILITY DETAILS
I found a dead end on the find my device, while i was testing out my new phone. The process that I went through came to a dead end which will result the user to not find their device. I believe this is a legitimate problem and I want to know if this would qualify to the Rewards Program and how much would be the reward if ever it is one.
 
Can you elaborate on what you mean when you say "dead end on the find my device"? What exactly did you do, and what precisely happened? Screenshots may help diagnose the issue.

If you're asking about the "Find My Device" app on Android, this isn't the right place to report problems, but depending on the answers to my questions, we can help route your issue appropriately.

Comment 2 by raymes@chromium.org, Jan 30 2018

Labels: -Type-Bug-Security -Restrict-View-SecurityTeam Needs-Feedback Type-Bug
This doesn't sound like a security issue. Removing the security label. 

monpronuevo@gmail.com please note this bug is now publicly visible so please avoid publishing any sensitive information.
I was trying to find my new phone via google search. "find my device" then it asked me to sign in then i have a two verification step which is the dead end. I can fully explain with screenshots. 

Project Member

Comment 4 by sheriffbot@chromium.org, Jan 30 2018

Cc: raymes@chromium.org
Labels: -Needs-Feedback
Thank you for providing more feedback. Adding requester "raymes@chromium.org" to the cc list and removing "Needs-Feedback" label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Comment 5 by raymes@chromium.org, Jan 30 2018

Labels: Needs-Feedback
Please do post screenshots.
I attached it here and I uploaded it as well on this site: 
https://i.imgur.com/lcrOTq3.jpg

Follow these steps while looking at the screenshot.

1. Type find my device on google search. Its gonna ask you to sign in again on your gmail.
2. Sign in with your gmail. 
3. Now here comes the tricky part. Since I have a 2-step verification on, its asking me to send a text message on my phone. Which would be very impossible to do since I don't have my phone with me, right now its "lost".
4. I tried the "more options" There's only 2 option which is the same thing.
5. On the same screen i tried to get help.
6. This is where the dead end is. There's no other way, which is to request Google's help which directs me in trying to recover my gmail account which I do not need because I did not lost my account login.

problem.jpg
453 KB View Download
Project Member

Comment 7 by sheriffbot@chromium.org, Jan 31 2018

Labels: -Needs-Feedback
Thank you for providing more feedback. Adding requester "raymes@chromium.org" to the cc list and removing "Needs-Feedback" label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Comment 8 by raymes@chromium.org, Jan 31 2018

Status: WontFix (was: Unconfirmed)
Thanks monpronuevo. Unfortunately, because you have 2-factor authentication turned on and because you have lost access to your phone, you will need to do a full account recovery by contacting Google: https://accounts.google.com/signin/recovery?hl=en. It isn't enough to have the username and password. 
@raymes

That's the issue that i am telling you about, so let's say there will be half millions of people lost their phone in 1 day and they wanted to track it and half millions of them have 2-factor authentication turned on, do you want all of them to go through the full account recovery option.
Re #9: Yes, when 2-Factor is enabled, by-design, 2-Factor is required. 

However, the Chrome bug tracker is not the appropriate venue for this discussion, as no one here works on the Google Accounts service and thus no one here can speak about it in any official capacity.

Sign in to add a comment