Live data from Hacker News

Ask HN: Gmail account security

news.ycombinator.com

191–200 of 807 posts

Re: Ask HN: Gmail account security

#191

One day I logged in to my Amazon account from a different country. Mind you, I have 2FA/OTP enabled in my account, and I entered it correctly. They also made me click on a link they sent via email to "verify my login". A couple hours later my account was blocked due to "suspicious login(s)" (i.e. mine), and the order I placed cancelled. They had me wait 24h until I could contact someone at support that could unblock…

Amazon's security is completely bonkers.

I lost access to my old account and they just decided that I will never change my password there.

To unblock I must provide them with proof of identity.... that includes: - notary certified copy of my passport, in English... (I'm not from an English speaking country) - proof of residence in Ireland, where I wasn't even resident, but I did receive a few packages

or.... I could just call my old phone number and ask the person to just forward me a text that they send to that phone number.

I mean... How over the top are the requirements, while someone with a damn leaked password database and access to my old phone number will be able to just "sail through"...

My AWS/Amazon accounts don't even have any activity or data in them...

Re: Ask HN: Gmail account security

#192

One day I logged in to my Amazon account from a different country. Mind you, I have 2FA/OTP enabled in my account, and I entered it correctly. They also made me click on a link they sent via email to "verify my login". A couple hours later my account was blocked due to "suspicious login(s)" (i.e. mine), and the order I placed cancelled. They had me wait 24h until I could contact someone at support that could unblock…

The amount of trust that providers put in phone numbers is absolutely insane.

I agree. I change my phone number often and this is annoying.

It's also very annoying that most EU banks rely on SMS codes to confirm transactions as it's quite easy to clone SIM cards. Yet they don't support real OATH OTP.

I hate Office 365, but I have to concede that their login is much more robust. I use passwords + OATH and it's truly reliable.

Gmail has locked me out very often for no clear reason. Besides they don't support TOTP unless you use a key or a phone app. So I can't use an airgapped device to store my keys.

Re: Ask HN: Gmail account security

#194

Earlier quoted context omitted.

The amount of trust that providers put in phone numbers is absolutely insane.

That aspect is significantly worsened if your country has had proper electronic IDs for nearly two decades. I laugh my ass off but also shed a tear each and every time some foreign provider asks for "identification". Security questions, electrical bills and selfies, medieval garbage. But I guess I should be happy fax usage has dwindled somewhat.

Fax usage has not dwindled at all for hospital medical records; it's still the primary way of transferring records from one hospital to another if they don't have the same computer software running the hospital. It's ridiculous.

Re: Ask HN: Gmail account security

#195
Looking at all the Google, Amazon, PayPal and comments on many others, security UX is simply an unsolved problem.

I am wondering if YubiKey would have the same problem? Edit: Looks like not.

Re: Ask HN: Gmail account security

#196
I think we, "people", pushed companies to do this.

There are billions of people creating various accounts. Hundreds of thousands of them had a weak password, or told their password to someone, etc, and their data leaked. There were so many news about "data leaks" and "security issues" in the past 20 years, and each time, a company was blamed, never a user.

We even made laws, where letting people log in with only a password can be illegal.

Re: Ask HN: Gmail account security

#197
post #77
post #27

Earlier quoted context omitted.

> Needless to say, I will never again use gmail for critically important things. That's a hot take. If it was critically important, you'd have 2FA and a recovery phone number associated with it - which would have prevented you from getting stuck in a trust-fail situation to begin with. Use whatever service you want, but your takeaway from this situation is a bit absurd. Edit to add: I'm not saying Google's algorithm…

I have 2FA and a recovery email on my Gmail account, yet I have run into this issue. If Google thinks something is suspicious, it will decline your 2FA codes and recovery attempts—it will just tell you that you entered the wrong code. Only after you finally get back in do you find an email in your inbox explaining that the correct code was entered, but Google blocked it because it was suspicious. This happens to me f…

I think we need to quit calling it AI, and instead call it AS: Actual Stupidity

Re: Ask HN: Gmail account security

#198
post #27

Had this. It was telling me to try again 'later'. Ok, i did 'try later' every day for three weeks, and they didn't let me in. Using the very same IP address as I used to always access it, no less. Then, I gave up, moved all my services to another email account, and after 2 or 3 months tried logging in, and it suddenly allowed me to log in. Needless to say, I will never again use gmail for critically important things.

> Needless to say, I will never again use gmail for critically important things. That's a hot take. If it was critically important, you'd have 2FA and a recovery phone number associated with it - which would have prevented you from getting stuck in a trust-fail situation to begin with. Use whatever service you want, but your takeaway from this situation is a bit absurd. Edit to add: I'm not saying Google's algorithm…

The only way to avoid getting into a trust-fail situation with Google is to be completely signed into it at all times so they can monitor you 24/7.

Re: Ask HN: Gmail account security

#199

Earlier quoted context omitted.

The amount of trust that providers put in phone numbers is absolutely insane.

That aspect is significantly worsened if your country has had proper electronic IDs for nearly two decades. I laugh my ass off but also shed a tear each and every time some foreign provider asks for "identification". Security questions, electrical bills and selfies, medieval garbage. But I guess I should be happy fax usage has dwindled somewhat.

LOL!

I just had an email from Mouser(online electronics store), that gave me the option to send in export for by fax...

Re: Ask HN: Gmail account security

#200
post #17

I'm having a hard time getting my head wrapped around the idea of relying on Gmail (or any other online identity provider) without enabling 2-factor authentication. The best way to avoid this kind of "AI hell" is just to take control of your own account security and set up some additional factors.

One of the main reasons why I don't want to activate 2FA in my Google account is precisely because while I don't have highly sensitive data in that account, I do have lots of convenient things that I need in a day-to-day basis, so I wouldn't want to be locked out of my account. And 2FA provides more ways in which this can happen (for example, the smartphone with the authenticator program breaks). So now the option is…

> for example, the smartphone with the authenticator program breaks

There are 3rd party authenticator apps (not Google Authenticator, though) that will allow you to seamlessly back up and restore the 2nd authentication factor, even to a different device. Ideally, it then becomes no less convenient than a password.

Post reply on HN