Live data from Hacker News

Ask HN: Gmail account security

news.ycombinator.com

181–190 of 807 posts

Re: Ask HN: Gmail account security

#181
post #126

Nearly every interaction I have had with Google in the last two years makes me think the company has devolved into warring factions that cannot communicate let alone coordinate for the betterment of their users. Do they not eat their own cooking, or how do they manage to make everything so dysfunctional?

Perhaps remote work doesn't lend itself to a well coordinated company?

Re: Ask HN: Gmail account security

#182

Earlier quoted context omitted.

Fastmail's UI is just faster too.

It's too bad their app doesn't have offline support. I use that feature of Gmail app a lot

On iOS and macOS I just use the standard Mail.app. Works well and even push notifications work.

Re: Ask HN: Gmail account security

#183
It keeps locking out my printer for using LDAP. It's extremely annoying to go and re-check the "yes, allow 'insecure' access" every N months. I complain a lot in the box, but obviously nobody is reading them.

Re: Ask HN: Gmail account security

#184
post #108

Earlier quoted context omitted.

Set up a real email provider, forward your mail from google to them, and transition over. If you want real identity security, reg your own domain, and move it with you.

> If you want real identity security, reg your own domain, and move it with you. I'm pretty confident that Gmail is more secure than the domain registrar if you're really attacked. At least do your research carefully on this one. Domains do get stolen. As always, consider your own threat model. But if you're a civilian? Wow, just hope you can walk away from the lockout.

I am my own domain registrar.

Re: Ask HN: Gmail account security

#185

One day I logged in to my Amazon account from a different country. Mind you, I have 2FA/OTP enabled in my account, and I entered it correctly. They also made me click on a link they sent via email to "verify my login". A couple hours later my account was blocked due to "suspicious login(s)" (i.e. mine), and the order I placed cancelled. They had me wait 24h until I could contact someone at support that could unblock…

It's incentivized top-to-bottom. Every audit is structured around checking boxes, absolutely zero interest in actual security. Just state you have processes, that they meet the loosely written (or in some cases bizarrely specific) spec, and be able to provide some writing that explain them at least at a surface level. This is the case for just about every framework, and even though these systems are just for window d…

They want us to be compliant, not secure:

https://www.go350.com/posts/they-want-us-to-be-compliant-not...

Re: Ask HN: Gmail account security

#186
I had a similar case, in one of my (lesser) gmail accounts. I took that as final warning and since then started to move away from google mail.

Currently, I use a posteo mail, which costs me 1€ (I believe) per month, for the important stuff. Mails which come as part of my webhosting package for most of the other stuff. And a free adress (web.de) as experiment, but it didn't turn out too bad so I keep it for unimportant stuff They just send ads as mail once a week. Calling this "mildly annoying" is exaggerated already.

Yea, so the takeaway (imo) is, leave the sinking ship before it sinks you. The process may take weeks or months if you proceed it relaxed (that's how I did it), so start before one of your important addresses gets hit.

Re: Ask HN: Gmail account security

#187
post #176
post #67

They also do this thing now where they block [1] smaller browsers (even ones using the latest version of chromium) under the guise of security. According to their docs they're fighting MITMs by generally disallowing any browser they can't identify (so the big few). If you're not on a whitelisted browser by Google, you can't log in (effectively, use) any of their properties. This feels very anti-competitive to me. Not…

Wow, that's awful. I wonder who's idea it was? Is it doing anything more than checking user agent (trivial to spoof), because if not that seems entirely hostile.

It's not just the user-agent, it is definitely doing non-trivial fingerprinting (both linked projects also had UA mitigations before). We don't have an easy workaround (besides a sketchy cookie hack that took hours to reverse engineer) right now and have been trying to get in touch with them.

Re: Ask HN: Gmail account security

#188

Had this. It was telling me to try again 'later'. Ok, i did 'try later' every day for three weeks, and they didn't let me in. Using the very same IP address as I used to always access it, no less. Then, I gave up, moved all my services to another email account, and after 2 or 3 months tried logging in, and it suddenly allowed me to log in. Needless to say, I will never again use gmail for critically important things.

My solution is, buy your own domain. It's cheap and it will cost you only 20$ a year or something like that. I'm not saying run your own email service (I do, but I recognize that it's complex and not worth for most people), but use a public email service (like also GMail) with your own domain.

That way at least if you no longer can access your account, or you get banned, or whatever, you don't loose your address (since you can just move to another provider).

Also, use an email client on your PC (such as Thunderbird) and configure it to keep a copy of all your emails locally (and possibly have the PC backed up). That way if you loose access to your account you don't loose access to your mail, that you can even upload again in the new provider server.

Re: Ask HN: Gmail account security

#189
post #67

They also do this thing now where they block [1] smaller browsers (even ones using the latest version of chromium) under the guise of security. According to their docs they're fighting MITMs by generally disallowing any browser they can't identify (so the big few). If you're not on a whitelisted browser by Google, you can't log in (effectively, use) any of their properties. This feels very anti-competitive to me. Not…

I'd guess that it's because they (incorrectly) think it's an embedded Webview, which get blocked (see https://developers.googleblog.com/2021/06/upcoming-security-... and https://developers.google.com/identity/protocols/oauth2/poli...).

You could try creating an issue in the Cloud Identity issue tracker (Cloud Identity is Google's API for letting websites have a "Login with Google" thing): https://issuetracker.google.com/issues/new?component=522910&...

Re: Ask HN: Gmail account security

#190

Earlier quoted context omitted.

It's incentivized top-to-bottom. Every audit is structured around checking boxes, absolutely zero interest in actual security. Just state you have processes, that they meet the loosely written (or in some cases bizarrely specific) spec, and be able to provide some writing that explain them at least at a surface level. This is the case for just about every framework, and even though these systems are just for window d…

I recently quit my job in Information Security. We used the NIST 800-53 framework. 99% of people following security frameworks just blindly check in boxes during audits or control assessments. A security control/requirement can’t be met? No problem! Just create another piece of paperwork accepting the risk and get it signed off by the system owner (who has the most incentive to not inconvenience their project or depa…

I was working for one of the Big 4 in risk assessment and this is 100% how it works.
Post reply on HN