Live data from Hacker News

Ask HN: Gmail account security

news.ycombinator.com

121–130 of 807 posts

Re: Ask HN: Gmail account security

#121

One day I logged in to my Amazon account from a different country. Mind you, I have 2FA/OTP enabled in my account, and I entered it correctly. They also made me click on a link they sent via email to "verify my login". A couple hours later my account was blocked due to "suspicious login(s)" (i.e. mine), and the order I placed cancelled. They had me wait 24h until I could contact someone at support that could unblock…

Wechat does this to me just to use the app. They keep making me play stupid recaptcha games and do verification codes then ultimately block me anyway. I finally gave up on using it.

Re: Ask HN: Gmail account security

#122

Earlier quoted context omitted.

The amount of trust that providers put in phone numbers is absolutely insane.

Or maybe do they really want your phone number? (Uninformed guess but isn't it valuable data?)

I’ve always figured this was what they wanted. They probably tie it to your IMEI so they can track you everywhere online and in the real world.

E: Seriously? This is a multi billion dollar industry. Oh no, Google would never do that

Re: Ask HN: Gmail account security

#123

Oh god, have you had the M.C. Escher-esque experience of trying to sign in to an email account, and it hits you with a two-factor-auth prompt that sent the code to another email address? Imagine the insanity if the email account that received the code in turn asks for a code sent a code to the first one.

Escher or Kafka? So far as I can tell, 2FA in a low touch environment means it is a matter of when not if you will be locked out without recourse.

Escher works in this case: 'Drawing Hands'. https://d279m997dpfwgl.cloudfront.net/wp/2018/02/0207_escher...

Re: Ask HN: Gmail account security

#125
post #44

Earlier quoted context omitted.

I'd suggest not to rely on google for anything you wouldn't want to lose.

2022 me agrees with you, but 2003 me getting an invite to GMail when it was a brand new service and essentially a completely different company with a different landscape didn't know better. Now I have nearly two decades of accounts and things tied to GMail =(

Google Takeout is a pretty nice service still. It's good to back up your accounts regularly.

Re: Ask HN: Gmail account security

#126
Nearly every interaction I have had with Google in the last two years makes me think the company has devolved into warring factions that cannot communicate let alone coordinate for the betterment of their users. Do they not eat their own cooking, or how do they manage to make everything so dysfunctional?

Re: Ask HN: Gmail account security

#127
Password reset functions for most providers often make 2FA hardware/software tokens useless. They fall back to email/sms to reset forgotten password/tokens. I guess it’s usability for majority over security that would lock out users.

Re: Ask HN: Gmail account security

#129
post #99

there needs to be some kind of law or regulation around this right? email has become as, if not more important as regular mail, and the government should be protecting access to it. try sending it to your senator and local representative. I think the FTC would also be interested in this. if google won’t even give you support for the issue, that should really be addressed by the government imo.

In my country the state maintains an alternative to email, where you can receive messages from anything government related, plus any business that registers. It's opt-in only, you cannot receive spam or be subscribed to entities against your will, and of course if you lose access you can just go down to the nearest citizen's office and get it sorted. You can also pay bills through it.

It is a nice solution but unfortunately everyone already has to have email accounts, so it becomes just yet another account to check, which is not attractive.

Re: Ask HN: Gmail account security

#130
post #27

Earlier quoted context omitted.

> Needless to say, I will never again use gmail for critically important things. That's a hot take. If it was critically important, you'd have 2FA and a recovery phone number associated with it - which would have prevented you from getting stuck in a trust-fail situation to begin with. Use whatever service you want, but your takeaway from this situation is a bit absurd. Edit to add: I'm not saying Google's algorithm…

With Google’s nonexistent customer service I’d be afraid of being locked out for any arbitrary reason and having no recourse no matter what recovery procedures I prepared for. Contrast that to my bank where I can go to the branch, show ID, and get problems logging in resolved.

FYI, google has customer service if you're paying them. I pay $6 a month for gsuite. I've contacted customer service 3 times. Got them instantly.
Post reply on HN