Ask HN: Gmail account security
71–80 of 807 posts
Re: Ask HN: Gmail account security
#72That doesn't help OP now, but I found it helpful to enable 2FA with Google Authenticator, and keep emergency backup codes in a safe place. It's slightly more hassle, but there are less 'soft AI' barriers between you and your successful login. I'd also suggest not to rely on a phone number as 2nd factor, it's not that super safe.
I’d recommend a non-Google 2FA app. Microsoft has one, and Authy is popular. Personally I’m happy with OTP Auth. Some password managers can also handle 2FA, e.g. Strongbox.
Re: Ask HN: Gmail account security
#73Wasn't aware of this, but can't say I'm surprised. Personally, I'm still happy with Fastmail, which uses customer subscriptions fees to fund a professional support department, as well as contributing to email-related FOSS. (Among other things, obviously.)
[0] FastMail loses customers, faces calls to move over anti-encryption laws https://www.itnews.com.au/news/fastmail-loses-customers-face...
[1] Goodbye FastMail https://www.ctrl.blog/entry/goodbye-fastmail.html
Re: Ask HN: Gmail account security
#74Earlier quoted context omitted.
Can I ask which news? I'm already a happy Fastmail customer, just curious.
This [1] Neat fact, Google is yet to tell me they are making this change to my account. [1] https://arstechnica.com/gadgets/2022/01/google-tells-free-g-...
Re: Ask HN: Gmail account security
#75Long-term solution: Stop using Google. Why? Not just because of this type of shenanigans, but because Google spies on you:
* It keeps a copy of all of your correspondence, even if you delete it.
* (Rephrased) The US National Security Agency (NSA) has gotten access to much of your correspondence, by tapping links between Google's data center; it may still have such access today and Google's extent of collaboration with this is not known for certain (to me anyway).
* It uses your correspondence and other information about you allow commercial companies to manipulate you with advertisement.
(The NSA part was verified by Edward Snowden's revelations, several years back; see: https://www.washingtonpost.com/world/national-security/nsa-i... for example)
Now, no third-party mail service is perfectly safe; but you should want one which is at least somewhat-safe, and that doesn't treat you unfairly.
I won't make specific recommendations, but I've personally had decent experience with ProtonMail (Switzerland) and gmx.com (Germany).
Re: Ask HN: Gmail account security
#76That doesn't help OP now, but I found it helpful to enable 2FA with Google Authenticator, and keep emergency backup codes in a safe place. It's slightly more hassle, but there are less 'soft AI' barriers between you and your successful login. I'd also suggest not to rely on a phone number as 2nd factor, it's not that super safe.
I’d recommend a non-Google 2FA app. Microsoft has one, and Authy is popular. Personally I’m happy with OTP Auth. Some password managers can also handle 2FA, e.g. Strongbox.
Re: Ask HN: Gmail account security
#77Had this. It was telling me to try again 'later'. Ok, i did 'try later' every day for three weeks, and they didn't let me in. Using the very same IP address as I used to always access it, no less. Then, I gave up, moved all my services to another email account, and after 2 or 3 months tried logging in, and it suddenly allowed me to log in. Needless to say, I will never again use gmail for critically important things.
> Needless to say, I will never again use gmail for critically important things. That's a hot take. If it was critically important, you'd have 2FA and a recovery phone number associated with it - which would have prevented you from getting stuck in a trust-fail situation to begin with. Use whatever service you want, but your takeaway from this situation is a bit absurd. Edit to add: I'm not saying Google's algorithm…
This happens to me from time to time, and the only way I can get back in is through Android. I keep an Android phone on hand at all times for this very reason.
Don’t blame the human for inadequate preparation; I assure you, no amount of preparation will save you from Google’s AI.
Re: Ask HN: Gmail account security
#78Earlier quoted context omitted.
> Needless to say, I will never again use gmail for critically important things. That's a hot take. If it was critically important, you'd have 2FA and a recovery phone number associated with it - which would have prevented you from getting stuck in a trust-fail situation to begin with. Use whatever service you want, but your takeaway from this situation is a bit absurd. Edit to add: I'm not saying Google's algorithm…
Something can be critically important for a person to access on-demand and not be something they’re especially concerned about an attacker accessing. Two completely unrelated dimensions of access needs.
Re: Ask HN: Gmail account security
#79Not defending the practice at all. It shows we as a society and Google in particular need better security if they are flat-out locking people out of their Gmail accounts and others are still being compromised (I know they are). I honestly support Google forcing people to use recovery addresses and 2-factor authentication but I don't support them making the recovery authentication not work and providing literally no options for a legitimate user.
I think the best you can do right now is complain on HN and Twitter and you'll probably get your account back. In the future, maybe if you have a YubiKey or stronger form of 2FA Google won't lock you out, because obviously if someone can authenticate with a YubiKey they are practically guaranteed to be the real person.
Re: Ask HN: Gmail account security
#80You might not like it, but then you're free to disable this IIRC?