Fone Forum
April 20, 2024, 12:23:58 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Fone Forum is pleased to welcome its valued guests and members.  We hope you will all enjoy your time with us, and find us a happy community of shared interests - who pool our knowledge, so that we can all come away better informed.  Wink  Cheesy  Grin
 
   Home   Help Search Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Want Gmail? Best have your mobile handy !  (Read 6817 times)
0 Members and 1 Guest are viewing this topic.
mobaholic
Administrator
Hero Member
*****
Offline Offline

Posts: 3117



WWW
« on: July 30, 2009, 10:03:25 AM »


Gmail starts taking numbers

According to TheRegister,

"Users signing up for a Gmail account are now being asked to provide a mobile-phone number in the continuing war against spam, though Google will keep it handy just in case anything else turns up.

The new requirement pops up as part of the Gmail sign-up procedure, and requires the user to provide an SMS-capable number to which a security code can be sent.  If you don't have a mobile then Google suggests you borrow someone else's, as those without one won't get a Gmail account anymore.

You might have thought that once the authentication has been received Google wouldn't need to hang onto your mobile number, but you'd have thought wrong:

"Your number will also be associated with your account to avoid unnecessary future verifications for other Google services", though the Do-No-Evil company does clarify: "your number will never be sold or shared for marketing purposes without your permission, nor will we contact you using this number without your express permission".

So that's OK then.

We contacted Google, who assured us this has nothing to do with harvesting numbers for an imminent launch of Google Voice on this side of the pond.  That is a shame, but our charging structure always made it very unlikely.

The decreasing cost of text messaging has driven many companies to resort to such out-of-channel security measures, and if it works at reducing the deluge of spam then that's got to be a good thing".

Logged

Valued guests are cordially invited to join.  Registration is quick & easy, & only needs an email address.  You can then benefit from contributing to our forum, & being able to use our PM system.

If you do not do so, but wish to make contact, you may email:-  theadminteam.foneforum@gmail.com
andy
Sr. Member
****
Offline Offline

Posts: 342


« Reply #1 on: August 14, 2009, 12:25:22 AM »

I just read something that might be the reasoning behind this

Someone discovered a security glitch, which allowed anyone with a Gmail account to guess another user's password 100 times in 2 hours, 1200 times a day. As many hackers might control well over 100 accounts, that gives a lot of guesses. So it recommends people adopt stronger passowrds, as many don't need all that many attempts. Once cracked, the victim's gmail might be used to send spam

http://windowssecrets.com/comp/090806/#story1

http://seclists.org/fulldisclosure/2009/Jul/0254.html

« Last Edit: August 14, 2009, 12:27:16 AM by andy » Logged
mobaholic
Administrator
Hero Member
*****
Offline Offline

Posts: 3117



WWW
« Reply #2 on: August 14, 2009, 11:41:46 AM »

I just read something that might be the reasoning behind this

Someone discovered a security glitch, which allowed anyone with a Gmail account to guess another user's password 100 times in 2 hours, 1200 times a day. As many hackers might control well over 100 accounts, that gives a lot of guesses. So it recommends people adopt stronger passowrds, as many don't need all that many attempts. Once cracked, the victim's gmail might be used to send spam

http://windowssecrets.com/comp/090806/#story1

http://seclists.org/fulldisclosure/2009/Jul/0254.html

Thank you for this post andy.        Smiley

Although I can see the dangers of password detection and theft, it is not immediately apparent to me how this relates to the need for a mobile number to open an account ?        Undecided

Furthermore, if you are right about the underlying reasoning, surely the very first thing that gmail should have done is to mail all its readers advising them to change their passwords to ones less easy to crack ?         Shocked

If you see the line between cause and effect here more clearly than I do, perhaps we may look forward to your further thoughts please.        Wink

TIA.

Logged

Valued guests are cordially invited to join.  Registration is quick & easy, & only needs an email address.  You can then benefit from contributing to our forum, & being able to use our PM system.

If you do not do so, but wish to make contact, you may email:-  theadminteam.foneforum@gmail.com
andy
Sr. Member
****
Offline Offline

Posts: 342


« Reply #3 on: August 14, 2009, 11:54:01 AM »

well, the reasons may or may not be aligned, but one possible assumption from the text message requirement would be that Gmail had experienced networks of automated spambots signing up, and that a text message helps to prove a human connection, especially if Google keep the number and check it doesn't sign up for more than a few accounts

my speculation wonders if some of these spambots might also be trying to hack other accounts to increase their numbers
« Last Edit: August 14, 2009, 11:57:10 AM by andy » Logged
mobaholic
Administrator
Hero Member
*****
Offline Offline

Posts: 3117



WWW
« Reply #4 on: August 14, 2009, 12:04:45 PM »

well, the reasons may or may not be aligned, but one possible assumption from the text message requirement would be that Gmail had experienced networks of automated spambots signing up, and that a text message helps to prove a human connection, especially if Google keep the number and check it doesn't sign up for more than a few accounts

my speculation wonders if some of these spambots might also be trying to hack other accounts to increase their numbers

Thanks andy.  I follow your first point, and rather agree with the speculation in your second.        Smiley

« Last Edit: August 14, 2009, 01:51:50 PM by mobaholic » Logged

Valued guests are cordially invited to join.  Registration is quick & easy, & only needs an email address.  You can then benefit from contributing to our forum, & being able to use our PM system.

If you do not do so, but wish to make contact, you may email:-  theadminteam.foneforum@gmail.com
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.21 | SMF © 2015, Simple Machines Valid XHTML 1.0! Valid CSS!
Page created in 0.024 seconds with 18 queries.