My 87 year old grandma's computer wouldn't boot. We set her up on a new laptop. But we couldn't remember her Gmail password. We never recovered her account, including any photos backed up to Google Photos.
You should be able to image her hard disk, and probably boot it up in a VM. Windows activation might complain in that case, but her data will be there.
Ask HN: Gmail account security
721–730 of 807 posts
Re: Ask HN: Gmail account security
#722Absolutely outrageously dangerous system, no way I can trust that service with anything remotely essential again.
Re: Ask HN: Gmail account security
#723Re: Ask HN: Gmail account security
#724They also do this thing now where they block [1] smaller browsers (even ones using the latest version of chromium) under the guise of security. According to their docs they're fighting MITMs by generally disallowing any browser they can't identify (so the big few). If you're not on a whitelisted browser by Google, you can't log in (effectively, use) any of their properties. This feels very anti-competitive to me. Not…
Google sometimes blocks me from searching using Firefox, saying it’s “suspicious activity” and sending me into captcha hell that always rejects my results after several screens for no reason. It’s incredibly transparent as to what they’re doing. That Google became the most anti-consumer company out there is pretty disgraceful.
Re: Ask HN: Gmail account security
#725Earlier quoted context omitted.
Is this a niche waiting to be exploited?
Yes. The public good derived from sane EHR interoperability would be enormous. Lower costs, better treatments, more informed policies... But there are lots of political barriers. NHS is trying, and pretty open to private tenders. I'm actually working on a very related field. Smaller or more atomized healthcare systems than NHS would be probably even difficult to deal with initially.
What needs to happens is for the US federal government to issue a mandate: if a hospital wants to get federal dollars (Medicare, etc), its computer system has to comply with the FXHR rules (Federal eXchange for Health Records, or whatever they want to call it). To establish FXHR, they get the top 5 vendors in a room and tell them that they WILL come up with a data exchange protocol and format within x months. They did this with HIPPA, they can do it with data exchange too.
And it is sorely needed. I went to Mayo Clinic for a week, which generated 80 pages of medical reports. To get these transferred to my regular doctors, I had to call Mayo, request the transfer, and they had to schedule the transfer, which sometimes took up to a week. This isn't because they are inefficient (far from it). It's because when they do a fax, sometimes the fax machine isn't on, so it can't go through. They have to retry until they get through. The receiving machine ran out of paper. Etc. It's ridiculous.
Beyond that, I watched my eye doctor try to flip through 80 pages of crap that mostly didn't relate to him to find the pages that were eye related. None of this has any structure; it's just a bunch of pages of text. Horribly inefficient use of his time, and very likely he would miss something important. You want to see blood test results? Well, I had about 10 of them testing various things, and the lab results are spread all through the report. Good luck finding what you want. Truly a mess, and the large software companies have zero incentive to fix this problem. Their goal is to be "the one to rule them all", or at least one of the few. And when there are only a few, there still won't be any data exchange, because they will be duking it out with each other.
Government screws stuff up all the time, but so do private companies, and government is the only player in a position to force the private companies to do the right thing.
Re: Ask HN: Gmail account security
#726Earlier quoted context omitted.
> Needless to say, I will never again use gmail for critically important things. That's a hot take. If it was critically important, you'd have 2FA and a recovery phone number associated with it - which would have prevented you from getting stuck in a trust-fail situation to begin with. Use whatever service you want, but your takeaway from this situation is a bit absurd. Edit to add: I'm not saying Google's algorithm…
I have 2FA and a recovery email on my Gmail account, yet I have run into this issue. If Google thinks something is suspicious, it will decline your 2FA codes and recovery attempts—it will just tell you that you entered the wrong code. Only after you finally get back in do you find an email in your inbox explaining that the correct code was entered, but Google blocked it because it was suspicious. This happens to me f…
Re: Ask HN: Gmail account security
#727Earlier quoted context omitted.
Long time Firefox user and HNer here. I've at least been "captchaed" in Firefox. While being logged in with my Gmail account from 2005.
I've been "captchaed" with Chrome, so I'm not sure the anecdotes amount to much.
BTW: Yes, I absolutely noticed that you said this above:
> ...and the beauty of the Internet is that there's really no way to be sure people are being genuine...
My point is, unless the claims of the others are outrageous or we have something very specific to point at, I don't think voicing these kind of thoughts do much good.
Re: Ask HN: Gmail account security
#728Earlier quoted context omitted.
If you're entering a code, the 2FA method you're using is still susceptible to mitm-style phishing attacks, which is what this kind of location based check is securing against. You'd need a push notification or yubikey based 2fa check to get the same level of security.
I have several YubiKeys linked to my account. It will decline those as well. It demands that I sign in from Android sometimes, seemingly for no reason.
Re: Ask HN: Gmail account security
#729Earlier quoted context omitted.
If we reason from good faith and consider that this is intentional and not a bug, have you considered that Google did not implement "blocking suspicious 2FA" just to mess with you? That perhaps this deals with a very real threat? Google has no incentive to make it difficult for you to log in, it's the exact opposite.
I have no doubt it deals with a real threat. That doesn’t change the fact that I’m regularly unable to log into my Google account. Usually it happens when I’m using multiple devices simultaneously—for example, Android and iOS. It’s understandable that Google considers that to be suspicious, but if Google isn’t going to learn on its own, there needs to be some way for me to confirm that nothing is amiss. It’ll ignore…
Not saying it's not true (I believe you), just that it's not designed to be a suspicious case, at least.
Re: Ask HN: Gmail account security
#730Earlier quoted context omitted.
With Google’s nonexistent customer service I’d be afraid of being locked out for any arbitrary reason and having no recourse no matter what recovery procedures I prepared for. Contrast that to my bank where I can go to the branch, show ID, and get problems logging in resolved.
FYI, google has customer service if you're paying them. I pay $6 a month for gsuite. I've contacted customer service 3 times. Got them instantly.