Hacker News new | ask | show | jobs
by noisy_boy 4245 days ago
If I'm not mistaken, the attacker set call/msg forwarding on his phone via his telco and then they chose the "forgot my password" option where a SMS text from Google (now going to attacker's phone) can be used to reset the password.