EvilZone

Hacking and Security => Hacking and Security => Topic started by: feeltheburn on June 01, 2015, 11:06:18 PM

Title: Gmail: New sign-in from...
Post by: feeltheburn on June 01, 2015, 11:06:18 PM
Does anyone care to explain to me, what is the point of these email notifications on gmail?

[ Image in attachments ]

I mean, if it's supposed to notify me that a possible intruder has accessed my account- why does it send the notification during the intruders session when he can just delete the email ?


Title: Re: Gmail: New sign-in from...
Post by: gh05t3d on June 02, 2015, 02:34:13 AM
it means you accessed your account/email from an unknown ip not in their records.  it happens to me whe  i sign in from an  unsual device.
Title: Re: Gmail: New sign-in from...
Post by: feeltheburn on June 02, 2015, 07:08:21 AM
Ok, I understand, but what is the point of them notifying me about it?
Title: Re: Gmail: New sign-in from...
Post by: HTH on June 02, 2015, 07:32:39 AM
Would you like to know if some random person got your password and was using your google acount? I sure would, and thats the point.
Title: Re: Gmail: New sign-in from...
Post by: feeltheburn on June 02, 2015, 07:39:48 AM
And this brings us back to my question in OP:

Quote
I mean, if it's supposed to notify me that a possible intruder has accessed my account- why does it send the notification during the intruders session when he can just delete the email ?
Title: Re: Gmail: New sign-in from...
Post by: khofo on June 02, 2015, 01:40:05 PM
And this brings us back to my question in OP:



Because most people have their email signed in on their mobile devices or other conouters too, so when u check your emails on your phone you'll see the email. And know someone accessed your account.
I agree it is not the best way to notify the user but it's simple and effiecient as well as effective in most cases.
Title: Re: Gmail: New sign-in from...
Post by: yhi on June 02, 2015, 02:18:41 PM
i think they should send a sms alert to registered number & a mail to alternative email or recovery email

because a attacker can easily delete the email 
Title: Re: Gmail: New sign-in from...
Post by: techb on June 02, 2015, 03:15:41 PM
i think they should send a sms alert to registered number & a mail to alternative email or recovery email

because a attacker can easily delete the email

I would drop gmail as an email provider if they switched to something like facebook does. Just no.
Title: Re: Gmail: New sign-in from...
Post by: feeltheburn on June 02, 2015, 06:02:11 PM
Quote
Because most people have their email signed in on their mobile devices or other conouters too, so when u check your emails on your phone you'll see the email. And know someone accessed your account.
I agree it is not the best way to notify the user but it's simple and effiecient as well as effective in most cases.

I thought that this might be the case, but figured maybe there was something more to it :)

Maybe they should just wait for you to log in from you're usual address before sending the notification email?

Dunno, silly Google...
Title: Re: Gmail: New sign-in from...
Post by: Kulverstukas on June 02, 2015, 06:26:24 PM
@Khofo: if the guy uses IMAP on his phone, then it doesn't matter - it gets synchronized. POP3 on the other hand is just download.
I haven't really thought of this before... it would make more sense if they sent that email to your recovery mail, not the same mail...
Title: Re: Gmail: New sign-in from...
Post by: nrael on June 02, 2015, 09:07:25 PM
I think you can have an alternative mail, and like someone said you get the mail on your phone, at least the notification of it (and then you know somethings wrong).

And the "attacker" won't think about a login notification mail, at least not every attacker.
Title: Re: Gmail: New sign-in from...
Post by: yhi on June 02, 2015, 09:26:01 PM
@Khofo: if the guy uses IMAP on his phone, then it doesn't matter - it gets synchronized. POP3 on the other hand is just download.
I haven't really thought of this before... it would make more sense if they sent that email to your recovery mail, not the same mail...

I think you can have an alternative mail, and like someone said you get the mail on your phone, at least the notification of it (and then you know somethings wrong).

And the "attacker" won't think about a login notification mail, at least not every attacker.

lol
this is first time someone here think what i said was right :P
m soo happy :P
Title: Re: Gmail: New sign-in from...
Post by: proxx on June 02, 2015, 10:47:18 PM
Also the interesting part about it is that most accounts are used for other services which become instantly available.
Title: Re: Gmail: New sign-in from...
Post by: nozzlechunks on June 17, 2015, 08:55:10 PM
You might have your Gmail already on another device, and when this pops and the log-in is originating from the North Pole, you know some shiz has gone down.

Also, it attacker wants to continue to dip into your emails and keep reading them, or keep sending spam from your account, or keep carding with your shop sites, they aren't gonna' change your password, cuz you'll contact the Googles and get your account back. Better for attacker to go slow and low.