Live data from Hacker News

Ask HN: Gmail account security

news.ycombinator.com

281–290 of 807 posts

Re: Ask HN: Gmail account security

#281

As a security professional, this is something we deal with daily. Security is too lax? Why didn't you protect my data. Security is too strong? I can't easily access my data! Can someone show me the Goldilocks zone for internet security? It's a moving target.

Goldilocks for me is not allowing brute force password attacks and trusting me to create a non-worthless password.

Re: Ask HN: Gmail account security

#282
post #17

I'm having a hard time getting my head wrapped around the idea of relying on Gmail (or any other online identity provider) without enabling 2-factor authentication. The best way to avoid this kind of "AI hell" is just to take control of your own account security and set up some additional factors.

Unless you have an older account, rarely used except to forward email to another address, and google unilaterally decides to lock you out without telling you they're changing their policy. Apparently the big google brain decided somebody other than myself guessed my 40 random char password. I've long decided I will never be able to login to my gmail account.

I forget now why I was originally trying to login. I may have been trying to setup 2fa even. Not gonna happen now.

Re: Ask HN: Gmail account security

#283

Earlier quoted context omitted.

A plug from a very satisfied customer: I pay $5/month for Fastmail. I've emailed support before and reached a human within hours. They helped me with my problem, because it was their job and I'm paying them to do it. Email is too important to rely on a free service which has a history of shutting people out, at any time, for any reason.

Reasonably confident one of my support tickets even got answered by the CEO once. They're a shockingly human-focused company.

Yeah, likely - I've answered a few tickets here and there :)

Re: Ask HN: Gmail account security

#284
post #67

They also do this thing now where they block [1] smaller browsers (even ones using the latest version of chromium) under the guise of security. According to their docs they're fighting MITMs by generally disallowing any browser they can't identify (so the big few). If you're not on a whitelisted browser by Google, you can't log in (effectively, use) any of their properties. This feels very anti-competitive to me. Not…

A browser environment designed for researching is something I've been investigating lately. I want to stay with Chromium for convenience (Chrome for work, ungoogled-chromium for personal). Right now I see two paths that might work for me:

- A standalone browser that I use only for research purposes. Currently evaluating Bonsai [1] and am interested in Synth.

- A suite of tools that makes bookmarking and organizing easier when used alongside Chrome. Currently, I pay for Raindrop [2] to manage bookmarks, most likely will pay for Slapdash [3] for indexing, and am evaluating Heyday [4].

For an end-user like me, I would much rather pay for an extension+SaaS for Chrome or Firefox, rather than deal with workarounds for browser incompatibility.

[1] https://bonsaibrowser.com/ [2] https://raindrop.io/ [3] https://slapdash.com/ [4] https://heyday.xyz/

Re: Ask HN: Gmail account security

#285
post #195

Looking at all the Google, Amazon, PayPal and comments on many others, security UX is simply an unsolved problem. I am wondering if YubiKey would have the same problem? Edit: Looks like not.

Google has a good Yubikey implementation (they allow multiple keys), Amazon and PayPal are 100% crap implementations.

I had a website with probably 10K monthly active users go down for a week because I was travelling with a different Yubikey and AWS only allows 1 Yubikey to be registered.

I've also had PayPal payments have to be delayed until I got back home because of the same reason, they only allow 1 Yubikey.

Horrible quality products.

Re: Ask HN: Gmail account security

#286
post #67

They also do this thing now where they block [1] smaller browsers (even ones using the latest version of chromium) under the guise of security. According to their docs they're fighting MITMs by generally disallowing any browser they can't identify (so the big few). If you're not on a whitelisted browser by Google, you can't log in (effectively, use) any of their properties. This feels very anti-competitive to me. Not…

Kind of unrelated to the whole Google thing, but this Synth browser is a really cool idea. I'll read more into it when I get the chance!

Re: Ask HN: Gmail account security

#287

Had this. It was telling me to try again 'later'. Ok, i did 'try later' every day for three weeks, and they didn't let me in. Using the very same IP address as I used to always access it, no less. Then, I gave up, moved all my services to another email account, and after 2 or 3 months tried logging in, and it suddenly allowed me to log in. Needless to say, I will never again use gmail for critically important things.

My solution is, buy your own domain. It's cheap and it will cost you only 20$ a year or something like that. I'm not saying run your own email service (I do, but I recognize that it's complex and not worth for most people), but use a public email service (like also GMail) with your own domain. That way at least if you no longer can access your account, or you get banned, or whatever, you don't loose your address (sin…

I did this! Kind of. I bought a domain and was lucky enough to get in to a custom domain email (and more) service with a big company years ago when they had a free version.

Unfortunately... it was Google (so kind of hiring the wolf to care for my sheep, as it turns out).

And now they're cutting off all of us free tier folks. Which I can't fault them for, but still blame them for. Because I'm petty and entitled or whatever.

Re: Ask HN: Gmail account security

#289
Same sort of problem. I have an account like that which was giving these messages and after trying a lot of things over few weeks I gave up.

Some long time later (year+) I retried and got in. I attempted to change the security settings, but it wouldn’t let me.

Some long time later again, I’m now locked out again.

This whole thing is ridiculous. I know the password, and have access to the account to which it forwards all emails. It should be obvious that their is no IP address which regularly uses this account, and that they are clearly locking out the account owner for no good reason.

Re: Ask HN: Gmail account security

#290
post #228

Earlier quoted context omitted.

There is not need for a law. Just don't use google.

If someone wants to stop using gmail, it's horribly inconvenient to move to another service. You need to update your email with all your other accounts, which for most people is pretty much unfeasible. You can't take your @gmail.com address, which means switching email providers is extremely difficult. There should really be some consumer protection laws around email.

Email forwarding makes migrating away from Gmail substantially easier:

https://support.google.com/mail/answer/10957

With this, you don't have to update your email on all of your accounts at once. You can do it at your own pace.

Consumer protection laws requiring data portability would still be welcome.

Post reply on HN