160 comments

[ 2.1 ms ] story [ 243 ms ] thread
Happened to my phone this afternoon. Odd, but thought it was because of my vpn bouncing my IP around.
(comment deleted)
Started happening around noon pacific for me.
I assumed this was a reset from Google due to the Cloudflare stuff, but seems like it wasn't?
That was my first thought. Maybe accounts with google credentials exposed in some way had a forced logout to invalidate exposed auth token?
I would be surprised if Gmail sent any tokens or credentials via Cloudflare
Fear might be shared email/passwords since thats really common.
What's the fear? Aren't all passwords encrypted on the server side?
But if an in-transit plaintext password is leaked by CloudFlare, server-side encryption is irrelevant.

(... that said, it's not like revoking sessions would impede a password-holding adversary...)

It would for users that have 2FA enabled.
Third party sites where the Google account was used for authorization, could have transmittted data through Cloudflare. (Think "Log in with Google" button on millions of sites.)
Perhaps they are worried about active oauth tokens having leaked?
Does Google use cloudflare? Don't they do everything themselves?
Yes. They integrate as a proxy for Google's cloud stuff.

https://blog.cloudflare.com/cloudflare-is-now-a-google-cloud...

Not quite. CloudFlare is available to users of Google Cloud, but Google services don't use CloudFlare.

The only exception I could imagine would be some service that was brought in as part of an acquisition but has not yet been migrated to Google's internal platform. Obviously not applicable to products like Gmail or other core G Suite apps.

Well, he said that it wasn't. But then refused to say more, and disabled comments.

Strange.

I would imagine that was because the comments are intended for discussion about that particular issue, not for random users to jump in with wild conjecture on its impacts. Honestly not that strange.
> But then refused to say more

What more is there to say?

A link to an announcement on the issue?
Not in a random unrelated bug that people hijacked to discuss a different problem, no.

I think there's nothing special about refusing to discuss stuff there and disabling comments.

That's true, if it is "a random unrelated bug".

I suspect that there will be many such reports in coming weeks. And lots of denial, and refusal to comment.

That would have been the best outcome. As it is, I'm left with concerns. Maybe it is related, but he's been instructed to not comment. Maybe it's a National Security Letter. Or whatever.

And yes, maybe he was just stressed out, and didn't want to be pestered with conspiracy theory ;)

It's not strange at all?

Imagine you walked into a group of people, talking about one thing. You started talking about something completely random and different. They want to continue their conversation, you keep interjecting with questions about your random thing.

If they could, they'd probably turn you off so you couldn't talk, or go to another place to talk about it.

That's precisely what happened here.

he was nice enough to answer the off-topic question, and the person who asked decided not to believe him and continued to take the discussion further off topic. The only good way to handle that sort of thing is to lock the thread.
Happened to me. Signed out of all my devices & browsers!

I thought I was in sleep and had signed out of my mobile. But then same in mac. Then I thought some issue for sure.. And reports are here...!

Yeah, same here. I was trying to figure out if I had done something to trigger it or, worse yet, if I'd been "hacked" (or someone got close and Google noticed and killed all my sessions).
Happened to me as well, I was signed out of every device I use google on.
A lot of people probably left with accounts created for their Android phones and no idea what their password is.
Happened on one browser, of one device this afternoon. Other browser on the same computer, and other devices, were not impacted...

Like most here I assumed it was just a random, regular occurrence, and didn't pay much attention.

Happened on two accounts today.

ps: why the german text ?

I think google tries to get/guess your location and then gives you the language of that region.
Yes. If there only were a header that could tell the server which languages the user considers acceptable..

No, geolocation is probably a great idea. /s

(comment deleted)
This happened to me too. And having 2FA enabled makes it a pain when you are logged out of _all_ your devices. I checked my usage history but could not find anything. And this article really does not explain why.
I got logged out from multiple accounts on multiple devices. Today is being a pain :(
Same for me as well. I just assumed my account was being under potential compromise, changed password, etc.
Happened to me too this morning, all my devices (mobile, laptop, desktop) all signed out :S I thought something fishy going on.
Got a pop up on my mobile. How to check the pop up was not impersonated by a different app?
My thoughts exactly. Just close the popup and open any Google app to verify that you cannot access the app without signing in again.
On Mac it is so easy to steal a password. In Javascript: var gmailPw=prompt("Facetime requires your password to login"); Macos asks it every week/month for one reason or another, people are conditioned.
On some versions of android if you long press on the popup it will show you which app it's from. This obviously doesn't work for not-android and older versions, though.
Happened to me too, pain to log back in on google play (not allowed to paste password in)

It initially gave me a message that something had changed and I needed to log in again, I can't remember if that was on outlook (yes, I use outlook to get my gmail) or on google play.

> not allowed to paste password in

This kills me oh so very much.

AutoHotKey
Is that something for phone or computer? Because I was talking about my phone.

Would prefer if keepass2android had some autotype feature built in for android :D

It has. Don't use clipboard to propagate the password but use keepass2android's keyboard.
I actually thought that some sort of fishing attack is going on because my old password didn't work and I have to reset it.
Actually ended up wiping my phone because this coincided with a weird set of text attachments I got from someone who didn't knowingly send them. At that point I wasn't sure that my phone wasn't being keylogged, so I wiped to be on the safe side.
As in InfoSec guy, I confirm you did the right thing. Better be safe than sorry!
(comment deleted)
The text attachments were probably some mail agent mime parts mismatch.
Same happened to me last night, but only on my phone. It said something "had changed" in my account wtf.
Happened to my work account and my personal. Got a scary notification on my phone telling that "Something changed on my phone and I need to login again"
Only happened on my phone, not desktop/laptop. Haven't logged in as it could be some sort of attack. Any updates/info? Is a phone wipe in order?
Glad my Gmail account is no longer my primary email. Haven't seen issues with it on desktop, but my Windows phone is repeatedly spamming a "your Google account information is out-of-date" message.

Nothing in the Google Account panel for recently security changes though.

Ahhy my wife mentioned this happened to her this morning, she thought her account had been breached.
Happened to me too, only on a work email attached to a custom domain though and not on any of my Gmail.com ones. Strange.
At google's scale, it seems "some" === 10 million :-)
Seems not to happen on 2fa accounts
It happened on mine.
Happened on mine too. In Chrome I had to re-auth with 2FA, in iOS I just had to pick my gmail account from the account list without even reentering the password. Very strange.