Live data from Hacker News

Ask HN: Gmail account security

news.ycombinator.com

41–50 of 807 posts

Re: Ask HN: Gmail account security

#41
post #23
post #11

So in theory if someone was to ever accidentally or intentionally reset the location info for where all gmail accounts have logged in from, then effectively everyone would be unable to access their gmail account?

If that were to happen it would take about 5 minutes until this security feature would be deactivated.

If it happens to everyone then yes. But now imagine it happens to just you.

Re: Ask HN: Gmail account security

#42
post #32
post #20

Earlier quoted context omitted.

Google will still lock you out with 2fa. It’s pretty bad

Even with a FIDO2/U2F/WebAuthn key? If so, yeah that's pretty bad..

Yeah I got locked out dispite having printed codes and authy setup. Lasted a day or so

Re: Ask HN: Gmail account security

#43
post #6

I stopped using gmail. I pay for my own domain (approx $10 per year and subscribe a hosting service that costs about $4/month). The total cost is not much different from a paid google email which is about $50/year. If I happened to forget/lose all passwords (lost laptop, burned house etc.), I would probably need to deal with the hosting company who would try to identify me with my credit card or some other way (phone…

BTW A paid Google email via Workspace (previously G Suite) has gone up to $6/month/user, so $72 USD a year for a single user setup.

Re: Ask HN: Gmail account security

#44
post #16

That doesn't help OP now, but I found it helpful to enable 2FA with Google Authenticator, and keep emergency backup codes in a safe place. It's slightly more hassle, but there are less 'soft AI' barriers between you and your successful login. I'd also suggest not to rely on a phone number as 2nd factor, it's not that super safe.

I'd suggest not to rely on google for anything you wouldn't want to lose.

Re: Ask HN: Gmail account security

#45
post #7

Wasn't aware of this, but can't say I'm surprised. Personally, I'm still happy with Fastmail, which uses customer subscriptions fees to fund a professional support department, as well as contributing to email-related FOSS. (Among other things, obviously.)

Have you used Fastmail's support?

Yes. It’s great!

Re: Ask HN: Gmail account security

#47
post #24
post #21

Earlier quoted context omitted.

Do they offer an api?

yes, and it makes the gmail API look like a toy https://fastmail.blog/open-technologies/jmap-new-email-open-...

1password have an interesting article about integrating with FastMail using JMAP: https://blog.1password.com/making-masked-email-with-jmap/

Re: Ask HN: Gmail account security

#48
Happened to my grandma, who have had the same address for over 10 years. Was quite the ordeal to have her change over to a new adress once we decided it was meaningless to hope to regain access.

Re: Ask HN: Gmail account security

#49
post #16

That doesn't help OP now, but I found it helpful to enable 2FA with Google Authenticator, and keep emergency backup codes in a safe place. It's slightly more hassle, but there are less 'soft AI' barriers between you and your successful login. I'd also suggest not to rely on a phone number as 2nd factor, it's not that super safe.

I’d recommend a non-Google 2FA app. Microsoft has one, and Authy is popular. Personally I’m happy with OTP Auth. Some password managers can also handle 2FA, e.g. Strongbox.

Re: Ask HN: Gmail account security

#50
post #16

That doesn't help OP now, but I found it helpful to enable 2FA with Google Authenticator, and keep emergency backup codes in a safe place. It's slightly more hassle, but there are less 'soft AI' barriers between you and your successful login. I'd also suggest not to rely on a phone number as 2nd factor, it's not that super safe.

Would be good but on my accounts which didn't have 2FA, they seemed to have removed Authenticator as an option: only phone numbers available now.
Post reply on HN