Wasn't aware of this, but can't say I'm surprised. Personally, I'm still happy with Fastmail, which uses customer subscriptions fees to fund a professional support department, as well as contributing to email-related FOSS. (Among other things, obviously.)
Ask HN: Gmail account security
21–30 of 807 posts
Re: Ask HN: Gmail account security
#22Wasn't aware of this, but can't say I'm surprised. Personally, I'm still happy with Fastmail, which uses customer subscriptions fees to fund a professional support department, as well as contributing to email-related FOSS. (Among other things, obviously.)
Re: Ask HN: Gmail account security
#23So in theory if someone was to ever accidentally or intentionally reset the location info for where all gmail accounts have logged in from, then effectively everyone would be unable to access their gmail account?
Re: Ask HN: Gmail account security
#24Wasn't aware of this, but can't say I'm surprised. Personally, I'm still happy with Fastmail, which uses customer subscriptions fees to fund a professional support department, as well as contributing to email-related FOSS. (Among other things, obviously.)
Do they offer an api?
https://fastmail.blog/open-technologies/jmap-new-email-open-...
Re: Ask HN: Gmail account security
#25Just says "you can’t sign in" and that's it: https://i.imgur.com/4YrElkJ.png
Re: Ask HN: Gmail account security
#26Offline backups is a must at this point.
Re: Ask HN: Gmail account security
#27Had this. It was telling me to try again 'later'. Ok, i did 'try later' every day for three weeks, and they didn't let me in. Using the very same IP address as I used to always access it, no less. Then, I gave up, moved all my services to another email account, and after 2 or 3 months tried logging in, and it suddenly allowed me to log in. Needless to say, I will never again use gmail for critically important things.
That's a hot take. If it was critically important, you'd have 2FA and a recovery phone number associated with it - which would have prevented you from getting stuck in a trust-fail situation to begin with.
Use whatever service you want, but your takeaway from this situation is a bit absurd.
Edit to add: I'm not saying Google's algorithm is perfect here, but relying on heuristic voodoo ("I use the same IP, so I should be fine") for "critically important things" instead of using well-established means of securing access to critically important things (e.g. 2FA, backup mobile number) is a bit insane.
Re: Ask HN: Gmail account security
#28Re: Ask HN: Gmail account security
#29I'm having a hard time getting my head wrapped around the idea of relying on Gmail (or any other online identity provider) without enabling 2-factor authentication. The best way to avoid this kind of "AI hell" is just to take control of your own account security and set up some additional factors.
Even with 2FA setup, correct password correct TOTP, it did not let them in because it was suspicious. I also checked "it was me" in all their security alerts. It would only let the person in with sms based 2fa, which was a pain.
Re: Ask HN: Gmail account security
#30Wasn't aware of this, but can't say I'm surprised. Personally, I'm still happy with Fastmail, which uses customer subscriptions fees to fund a professional support department, as well as contributing to email-related FOSS. (Among other things, obviously.)
Fastmail's UI is just faster too.