Live data from Hacker News

Ask HN: Gmail account security

news.ycombinator.com

651–660 of 807 posts

Re: Ask HN: Gmail account security

#652
post #627

Earlier quoted context omitted.

It's pretty crazy to think about the fact that your email is de-facto your online identity, as it is the universal second factor that is used as a fallback if other login mechanisms fail. An email service is two things: a global name user@emailprovider.tld, which is really your online identity, and an email service that hosts the SMTP, IMAP and DNS services required for the identity to function. People are willing to…

The service you propose will either have the same problem as google, be vulnerable to social engineering attacks (like phone number providers), or be tied to extremely expensive infrastructure (e.g. enable post office or DMV offices to validate identity for the purposes of managing access to this account). Even if google had customer support agents, what do you want them to do in cases like this? They can't actually…

Yes, it would be "tied to extremely expensive infrastructure" ... that already exists. So no additional cost.

Re: Ask HN: Gmail account security

#653

Earlier quoted context omitted.

Interesting how the brand of security companies like Google keep telling us is in our best interests always seems to secure their corporate revenue streams first, while the security and freedom of users are an afterthought.

years ago I interviewed with a startup that was aiming to put their routers in various locations like airports and coffee shops. They would offer free or cheap internet at those locations. The catch: they were going to swap out ads with their own ads on the fly. Shortly after that, Google started pushing HTTPS. I never believed that was a coincidence.

The great migration to https, even for read-only self-hosted blogs, has been an amazing disservice to the world. Maybe if we had non-expiring ssl certificates with working OCSP or CRL, I’d have a different opinion.

Re: Ask HN: Gmail account security

#654

Earlier quoted context omitted.

> They once asked me to submit a business case justifying how answering my support question benefited Google. I find that extremely difficult to believe without more context. Google support isn’t that bad. I’ve had a mediocre-to-good experience with it over the years. With that said, while I agree that aws business and enterprise support is worth the hundreds to thousands of dollars a month, so is the five bucks a mo…

A few years back I wanted to call then but didn’t find a number. How do you contact Google’s support?

If you have a google workspace account and need google support, you can go in the admin console, help section in the top right, there is a contact form with phone and chat options.

Re: Ask HN: Gmail account security

#655
post #470

Earlier quoted context omitted.

You are actually pointing out a tremendous opportunity that Google has internally and externally. I work at Google and recently tried to file a bug about the calculator embedded in search. It was dastardly difficult to find how to file the ticket. It took me maybe an hour. A better system for filing tickets internally and for filing and triaging tickets from external users would be a tremendous asset for Google.

(edited) If you don't mind sharing, what is the bug? - My comment originally read as follows, 2 people downvoted it. >I work at Google and recently tried to file a bug about the calculator embedded in search. It was dastardly difficult to find how to file the ticket. It took me maybe an hour. A better system for filing tickets internally and for filing and triaging tickets from external users would be a tremendous as…

You just found a bug in Google Calculator. You wrote "calories" but Google is giving you the answer in "kilocalories". If you change "calories" to "kilocalories" the answer doesn't change.

I wonder how many times in the past has it given you the wrong answer without you noticing?

Re: Ask HN: Gmail account security

#656
post #627

Earlier quoted context omitted.

It's pretty crazy to think about the fact that your email is de-facto your online identity, as it is the universal second factor that is used as a fallback if other login mechanisms fail. An email service is two things: a global name user@emailprovider.tld, which is really your online identity, and an email service that hosts the SMTP, IMAP and DNS services required for the identity to function. People are willing to…

The service you propose will either have the same problem as google, be vulnerable to social engineering attacks (like phone number providers), or be tied to extremely expensive infrastructure (e.g. enable post office or DMV offices to validate identity for the purposes of managing access to this account). Even if google had customer support agents, what do you want them to do in cases like this? They can't actually…

In my country (Denmark) every person and legal entity has a government-issued digital identity (NemID) so the authentication process is trivial and cheap.

Re: Ask HN: Gmail account security

#657
Anecdotally, getting arbitrarily blocked and locked out of your stuff is the single biggest practical security today problem today for me (maybe it isn't for non-technical users who reuse weak passwords, install catpicture.jpeg.exes and random software from the internet, log in using public computers or other people's PCs..).

I don't believe I've ever had passwords compromised. The only time I know I had malware was when I was a kid and installed a runescape autominer.. I've had some close calls with software vulnerabilities (I patched opensmtpd mere hours before bots started attacking it), but that's rare. haveibeenpwned only shows involvement in the last.fm compromise, which is a no biggie since I wasn't 1) using the service any more 2) using the same password with other services 3) using that email address with anything worth caring about.

By contrast, I've been burned by service providers blocking me many many times. They call this security but how is the equivalent of "we decided to take all your mail and not deliver it to you, and changed the locks to your apartment so nobody can get in" security? It's security in the same sense as "we decided to burn all your money so nobody can steal it, hope you're happy."

As a consequence, I've tried to cut out as many services and third parties out of my life as I can. It's an uphill fight though, and most services are hell bent on adding points of failure. E.g. where my bank before supported OTPs (in addition to login & password), now they require a phone too. It's probably not a matter of if but when I get bitten by this; I've had a Samsung Xcover physically break.

I think any notion of security should include secure access for the relevant party. If you can't access your stuff, security has failed (unless it can be demonstrated that there was an active attack going on and the only way to prevent it was to block everyone.. which these overzealous blocking systems in place can't demonstrate).

Re: Ask HN: Gmail account security

#658

Earlier quoted context omitted.

It's pretty crazy to think about the fact that your email is de-facto your online identity, as it is the universal second factor that is used as a fallback if other login mechanisms fail. An email service is two things: a global name user@emailprovider.tld, which is really your online identity, and an email service that hosts the SMTP, IMAP and DNS services required for the identity to function. People are willing to…

I fully agree. Over the years I've been reading about people being locked out of their Gmail accounts, and the YEARS of pain they had to go through to try to regain access to the countless connected services. You don't realise how many hundreds of services require access to your email account until you lose access. The final straw was reading the heartbreaking account of someone who lost decades worth of personal pic…

Keep it up though. And encourage a friend.

Re: Ask HN: Gmail account security

#659
post #550
post #432

Earlier quoted context omitted.

"Papiere, bitte." (Just fyi. Mangling the German [sic] doesn't detract from your post.) Not sure being corporate centric makes this problem any worse? If you had other kinds of organisation, you'd still have to deal with abuse and fraud? Any people doing weird, unusual stuff, look inherently more suspicious. That's a fact of life in meatspace, too. There might be some utopian, ideal way to organise activity so that n…

> "Papiere, bitte." (Just fyi. Mangling the German [sic] doesn't detract from your post.) Thanks! > Not sure being corporate centric makes this problem any worse? If you had other kinds of organisation, you'd still have to deal with abuse and fraud? I think it's definitely not unique to big corps, but an emergent property of a distributed and homogenous system of self interested agents, probably. It feels very game t…

> I think it's definitely not unique to big corps, but an emergent property of a distributed and homogenous system of self interested agents, probably. It feels very game theoretical, at least. What's clear is these systems are becoming ubiquitous rapidly.

Not sure the homogenity is necessary?

To an extent, the market delivers what people are demanding.

For most people, Google's package of cheap or even free services with minimal hassle in the common case, but almost no recourse in bad cases, is compelling.

And for many it's a step up from having everything locally: I'd bet that more people lose their local data than get locked out of Google?

Re: Ask HN: Gmail account security

#660

Anecdotally, getting arbitrarily blocked and locked out of your stuff is the single biggest practical security today problem today for me (maybe it isn't for non-technical users who reuse weak passwords, install catpicture.jpeg.exes and random software from the internet, log in using public computers or other people's PCs..). I don't believe I've ever had passwords compromised. The only time I know I had malware was…

My 'favorite' is SMS and other proprietary app-based 2-factor auth.

My phone broke while I was traveling through Laos. I was going to be returning in a couple days, I could speak the language well enough, so I didn't have any immediate need to get a new phone (and the pickings were way too slim in a country such as Laos). What I thought would be a good idea was to purchase a new device online to be shipped to my apartment on my return. I tried to log into my online shopping account but most payments are always locked behind 2FA with SMS being the only option. Bank transfers worked too, but that as well was locked behind SMS. So in order to buy a new phone, I needed a new phone to buy a new phone. Almost nothing in the country support TOTP or WebAuthn, etc.. and the times they do they just call it "Google Authenticator" encouraging users give those keys to Google as well instead of supporting FOSS TOTP.

At the same time I got my income via TransferWise, and their 2FA is some proprietary BS in their app instead of generic TOTP that I can back up on my laptop. So I couldn't get extra money to my foreign account to pay for it.

A few months later I needed to use PayPal and was locked out of my account on similar grounds. My foreign account I didn't have my old phone number because it's pretty customary to rotate numbers on prepaid plans here, and my US account was using Google Voice (because it's tedious to maintain a US SIM card for the 2 times a year I need it) and they removed SMS support for Voice while not giving an alternative for authentication. The best part is that to get support from PayPal about authentication you needed to first authenticate to message support. Needless to say, I straight-up refuse to use PayPal now and direct message vendors about supporting an alternative (either widely or for this exception).

Post reply on HN