Liveness Detection: 6 Seconds to a Stolen Google Account
Liveness Detection: 6 Seconds to a Stolen Google Account
This episode is based on our article:
Read the full article →Liveness Detection: 6 Seconds to a Stolen Google Account
Full Episode Transcript
Six seconds. That's how long it took, in a demonstrated attack, for someone to log into a Google account and register their own device as a trusted key. The password change that came later? Didn't matter. They were already inside, permanently.
If you've ever set up face unlock or fingerprint
If you've ever set up face unlock or fingerprint sign-in on a phone, you've done exactly what those attackers did. You told an account, this device is me. That moment — the one that takes a couple of taps and feels like housekeeping — turns out to be the most important security decision in your entire digital life. And I want to be honest with you. This one is unsettling, because the technology being attacked is the technology we've all been told is finally safe. So how does an unbreakable system get broken?
Start with what a passkey actually is. When you sign in with your face or your fingerprint, your phone doesn't send your face anywhere. It holds a secret key and proves it has one. That math is genuinely excellent. Nobody in these attacks cracked it. Not once.
What they attacked was the moment before. The enrollment. The instant an account agrees to trust a brand new device it's never seen.
The article uses an analogy I keep thinking about
The article uses an analogy I keep thinking about. Picture a bank with a vault that opens only to a biometric scan. Rock solid. But the same bank lets you add an authorized representative at the front desk, just by showing a driver's license. An attacker doesn't touch the vault. They forge a license, walk in, and add themselves as an authorized person. From then on, they open the vault legitimately. The vault never failed. The front desk did.
So how does someone reach that front desk? Through the weaker door you probably didn't notice was still open. In the demonstrated attack, the victim didn't use their passkey at all. They typed a six-digit code from an authenticator app. According to the FIDO Alliance, offering passkeys next to passwords and one-time codes doesn't stop phishing — because people can still pick the weaker option. And a phished code hands the attacker a real, legitimate session.
For anyone with a phone, that's the practical takeaway. The strongest lock on your account only helps if the backup door is locked too.
The part that stopped me cold
Now, the part that stopped me cold. Most of these enrollments happen silently. Your original device gets no alert. No buzz, no email, nothing that says a new key was just added. Six seconds from login to enrollment. Compare that to how long it takes you to notice something's wrong, find the security settings, and revoke a device. The attack finishes before the defense even starts.
And here's what people get wrong, understandably. We hear "passwordless" and assume there's no weak link left, because the passkey itself really is phishing-resistant. That part's true. But a strong credential isn't the same as a strong account. Systems are built in layers, and attackers never attack the strongest layer. They go looking for the softest one.
Scale matters here too. The FIDO Alliance records five billion passkeys now in active use worldwide. Every one of those accounts has an enrollment gate.
The Bottom Line
Passwords weren't solved. The attack just moved. When there's no password left to steal, criminals go upstream — to the moment your account decides who counts as you.
So, three sentences. Passkeys are strong, and nobody broke the math. Attackers slip in through the weaker backup login, then quietly add their own device to your account. That "add a device" moment deserves the same suspicion you'd give a stranger asking to reset your password. So go look. Open your Google or Apple security settings tonight, find the list of devices and passkeys, and delete anything you don't recognize. That's not paranoia. That's five minutes that puts you ahead of a six-second attack. The written version goes deeper — link's below.
Ready for forensic-grade facial comparison?
Full forensic reports with detailed similarity scoring. Results in seconds.
Run My First SearchMore Episodes
Anti Facial Recognition Case: 168 Flagged, 1 Jailed 11 Hours
A truck driver walked into a Reno casino with a wallet full of I.D. — his Nevada license, his player card, his union card, even a pay stub. None of it mattered. A facial recognition system said he was
PodcastDeepfake Scams: One Fake Video Call Cost Her $287,000
A California widow lost at least two hundred eighty-seven thousand dollars to a man she never met. He appeared on video calls. He had a face, a voice, a job — he claimed to run the U.S. Naval Academy.
PodcastCCTV Facial Recognition: Why a 98% Match Proves Nothing
A ninety-eight percent facial recognition match sounds like certainty. But run that same ninety-eight percent threshold against a database of ten million faces, and you can still get hundreds of thousands of possible cand
