Live data from Hacker News

Ask HN: Gmail account security

news.ycombinator.com

251–260 of 807 posts

Re: Ask HN: Gmail account security

#251
post #7

Wasn't aware of this, but can't say I'm surprised. Personally, I'm still happy with Fastmail, which uses customer subscriptions fees to fund a professional support department, as well as contributing to email-related FOSS. (Among other things, obviously.)

I moved my family to Fastmail a couple months ago and it’s been wonderful. Never knew I wanted “shared contacts”, but it’s the best feature ever. Once I figured out it existed, I spent a couple days making really good cards for family members and family friends, and all that work is shared with the whole family.

Re: Ask HN: Gmail account security

#254
post #7

Wasn't aware of this, but can't say I'm surprised. Personally, I'm still happy with Fastmail, which uses customer subscriptions fees to fund a professional support department, as well as contributing to email-related FOSS. (Among other things, obviously.)

[deleted]

Re: Ask HN: Gmail account security

#255

Earlier quoted context omitted.

With Google’s nonexistent customer service I’d be afraid of being locked out for any arbitrary reason and having no recourse no matter what recovery procedures I prepared for. Contrast that to my bank where I can go to the branch, show ID, and get problems logging in resolved.

A plug from a very satisfied customer: I pay $5/month for Fastmail. I've emailed support before and reached a human within hours. They helped me with my problem, because it was their job and I'm paying them to do it. Email is too important to rely on a free service which has a history of shutting people out, at any time, for any reason.

Still the problem with Fastmail is the same as with Google. Leaning on 3rd party service that you have no control of. There are so many things that could go wrong there, they can be hacked, go bankrupt, closed by authorities, insided. Everyone should have an appropriate personal disaster recovery plan that includes stuff like recovering from loss of service supplier.

Re: Ask HN: Gmail account security

#257
post #176

Earlier quoted context omitted.

Wow, that's awful. I wonder who's idea it was? Is it doing anything more than checking user agent (trivial to spoof), because if not that seems entirely hostile.

It's not just the user-agent, it is definitely doing non-trivial fingerprinting (both linked projects also had UA mitigations before). We don't have an easy workaround (besides a sketchy cookie hack that took hours to reverse engineer) right now and have been trying to get in touch with them.

> it is definitely doing non-trivial fingerprinting

Can confirm.

To generalize and understand why, big corps have to deal with an insane amount of (often automated) abuse, so they build profiles using data collection to assess your risk level. Being in the wrong cohort (say unusual browser, small country, rare language, use a vpn etc) can affect your score. Basically it's these massive bayesian filters that output how suspicious some activity is. Whether you're signing in to Gmail, returning a product, buying something with a credit card or booking an Uber, some form of score is computed and then used to allow/deny/delay/verify. Obviously this is well established in the insurance and finance industries, but make no mistake, it happens everywhere.

This approach is understandable from a business perspective, but imo deeply troubling for an open society. You don't have to squint much in order to see the similarities to social credit systems, EVEN if there is no grand totalitarian state-coordinated behind it.

As usual, the first step is transparency so we can actually discuss these issues based on accurate data, but that's very difficult today. Usually fraud and abuse prevention is among the most secretive departments, they never share anything.

Re: Ask HN: Gmail account security

#258
Reminder: Google paid for an ad campaign with this gist: A father creates a Gmail account for his daughter when she is born, and sends her important photos and mementos as she grows up. Sweet. Reality: At least one person tried this in real life, and the child's account was automatically deleted without recourse.

https://tech.slashdot.org/story/11/12/18/2046221/why-google-...

Re: Ask HN: Gmail account security

#259

One day I logged in to my Amazon account from a different country. Mind you, I have 2FA/OTP enabled in my account, and I entered it correctly. They also made me click on a link they sent via email to "verify my login". A couple hours later my account was blocked due to "suspicious login(s)" (i.e. mine), and the order I placed cancelled. They had me wait 24h until I could contact someone at support that could unblock…

To be fair its not just Google and amazon etc. I had a similar issue with my bank, they blocked a transaction in online banking which had pre requisites of logging in (three secrets effectively) plus sms verification, and specific sms verification for this transaction. unblocking it required only control of my phone number and knowing my date of birth and other easy to get info. If it had been a fraudulent transaction then the bad actor already had my sim card and ability to log into my account.

Serious question: is there any examples of a robust way of doing customer security? Even just a proposal/document or blog post (doesn't need to have been implemented). I sort of feel no one has figured this out yet (if its even possible).

Companies just need to make sure their insurers will pay out, which if there is not proven solution seems about all they can do.. tho a little humility and honesty that that is their position would go a long way.

Re: Ask HN: Gmail account security

#260
post #230

It’s this kind of thing that has had me moving most everything off Google over the last 6 months. It’s just not safe for me to have 20 years of photos, emails and documents in the hands of a company that may cut me loose at any moment. After decades of slowly moving my life to “the cloud”, I bought a Synology nas, and now all my stuff lives in my own house (though backed up externally, of course).

Curious about the backup solution.
Post reply on HN