Bruteforcing any Google Account's Phone Number
A security flaw in Google's password reset form allowed potential doxing through email-to-phone number resolution, while a Defense Intelligence Agency worker attempted to betray the U.S. by offering classified information to a foreign government.
MAIN POINTS FROM TRANSCRIPT
- Google's password reset form vulnerability allowed email-to-phone number resolution.
- SIM swapping risks increase due to potential phone number exposure.
- Security researcher Brutecat discovered and reported the flaw to Google.
- A Defense Intelligence Agency worker attempted to share classified information with a foreign government.
TAKEAWAYS
- Google deprecated their no JavaScript account recovery form after the vulnerability was reported.
- Brutecat received a $5,000 reward from Google for his responsible disclosure.
- The vulnerability exploited Google's Looker Studio to obtain full names from email addresses.
- The Defense Intelligence Agency worker's betrayal was thwarted by the foreign government reporting him to the FBI.