Live data from Hacker News

Ask HN: Gmail account security

news.ycombinator.com

761–770 of 807 posts

Re: Ask HN: Gmail account security

#761

One day I logged in to my Amazon account from a different country. Mind you, I have 2FA/OTP enabled in my account, and I entered it correctly. They also made me click on a link they sent via email to "verify my login". A couple hours later my account was blocked due to "suspicious login(s)" (i.e. mine), and the order I placed cancelled. They had me wait 24h until I could contact someone at support that could unblock…

It's absolutely bonkers what stupid crap some companies would call "security", and what lengths they'd go to enforce it. - Security questions. Yeah, right, please give us what amounts to a password, but that other people likely know, and that we'll probably store in plaintext. You'll use this much weaker backup password if you forget your real one. - A time component. Any kind of it. Sessions should not have an expir…

> You want me to forget my password? Because this is how you make me forget my password.

   MySuperSecrit001
   MySuperSecrit002
   MySuperSecrit003
...

Re: Ask HN: Gmail account security

#762

Earlier quoted context omitted.

I moved my email to Fastmail this week in the wake of the Google Apps announcement. Having your own domain is great since your email becomes provider-agnostic. While Fastmail had a great import tool, I could have transferred my Gmail myself from backups. I'll be ready to do the same if Fastmail goes under or is no longer competitive.

I've heard this from a several posts this week. Genuine question: since maintaining GSuite is expect to cost $6/user/month and Fastmail costs $5/user/month, do you really find the $1/user/month in savings worth the trouble of moving email providers and losing Drive/Docs etc.? I'm planning a move too, but Fastmail's price doesn't strike me as competitive enough compared to Google's price. Amazon WorkMail is $4/user/mo…

There's going to be a lot of hassle, but I'm planning to move many of the Google services to old Gmail accounts. To some extent it's more of a justification to reduce reliance on Google. When running the numbers I was initially confused about the pricing for Gsuite and thought "standard" was the lowest tier ($10/month/user), so it's not the most strategic decision price-wise.

Re: Ask HN: Gmail account security

#763
post #733

Earlier quoted context omitted.

I'd rather know where my ship is burning instead of closing my eyes and just having happy thoughts. But then, I am an engineer, not some marketing drone...

Curious but how would you figure out where the ship is burning if you are receiving a larger number of bug reports, e.g. 1 million bug reports per month? Loads of duplication will also follow etc. Sounds like you need entire teams to figure out what the real bugs are at that point and maintain the bug list? Though I can't think of a workflow from the top of my head.

This very much is a solved problem - it comes down to standardization in tools, categorization of incidents, keyword analysis of incident description, and (probably automatable) correlation with logfiles and identifiers. Preventive maintenance is not a concept that has been around only recently, and a good QA team has a whole toolkit of things to throw at code before it hits the customer. And yes, ultimately, it is a question on whether you invest the resources to deal with the dumpster fire, or just let it burn to ashes. I am also a big believer in "You build it, you run it", and a "no new features as long as there are open bug tickets" approaches, making teams responsible for their own technical debt.

Google with it's "Let's never maintain our products, let the bitrot make them gradually worse and eventually EOL them" approach seems to prefer to avoid that kind of cost.

I used to be a Google fanboy in the early 2000s. Maybe it's coming with age, but these days I prefer boring tech that works well as compared than half-baked moonshots, and Google may have burned me once too many. Other software megacorps (and even some NGOs) do this better than the big G.

Re: Ask HN: Gmail account security

#764

Earlier quoted context omitted.

"I'd frequently tell my co-workers, "If you're not paying for it, you're the product."" But it sounds like this "extremely irate user" was paying for it.

Yeah, fair point. It's been several years, so maybe my memory of all the details is a bit hazy by now. I just recall that at one point one of the salespeople was addressing a point about something or other involving the user having paid for something. I have no idea whether the user was telling the complete truth (were they referring to something they used to subscribe to and don't any more?) or whether at the time w…

"Regardless I agree with other comments to the effect that even if you are paying, you are often still the product!"

The anaylsis needs to go further than whether one is paying or not. IMHO.

It is not rare to see HN commenters who appear to believe that the act of paying some "user fee" to a "tech" company that willfully caters to advertising, devotes almost all of its resources toward catering to advertisers, and derives almost all its revenue from advertising services, is somehow meaningful.

Re: Ask HN: Gmail account security

#765

Earlier quoted context omitted.

I use google constantly— sometimes hundreds of times per day— both logged in and out, almost exclusively in Firefox or Firefox developer edition and I've never encountered this. I'd bank on it being a network thing— VPN, overcrowded proxy, etc.

The beauty of AI is that it's likely no human can say precisely why two similar users might get a different classification.

I'm not saying the browser isn't a factor, or that Google isn't anti-consumer, or anything else. The original comment didn't say they were caught up in some unobservable AI machination. They made a pretty straightforward observation mentioning only two conditions: Google bounces them when using Firefox. From that, they jumped to a pretty straightforward conclusion— Google transparently harasses Firefox users to advance their corporate strategy.

I'm not going to jump through hoops to prove a negative, but correlation does not imply causation.

My empirical observation: For many years I have constantly used Google search on FF with many machines and networks, logged in and not, in private mode and not, with all existing privacy features enabled and no extensions beyond a password manager. Napkin math conservatively estimates I've conducted 200k searches minimum using this combo. I've consistently encountered suspicious activity challenges when using overcrowded proxies, NAT'd networks and VPNs. Removing those factors has never failed to stop the challenges. Ever.

I'm confident the poster's observations are accurate. My observation does not directly contradicts their observation, but it does contradicts their conclusion. I wouldn't be surprised if other factors like JS being enabled, cookie settings, plugins that affected those things, number of other users on their network, or even the public IP range they fall under would affect it.

Re: Ask HN: Gmail account security

#766
post #563

Earlier quoted context omitted.

I guess this is why Amazon is playing the long game with their obsessive focus on customers. I don't know how that really plays out where the rubber meets the road but that's what Jeff bezos always keeps talking about.

Really? I am locked out of my (10+ years old) account for almost two years, due to "security reasons" (I have valid OTP so I call this BS and my credit card has changed in between so the account is useless for anyone), they want me to call some number in states, but I am not giving my phone number away, which is also the reason why I don't create new account. I have calculations, in last two years I have bought 4378…

Just use a phone number from a service like temp-number.org. After logging in you will be able to remove it from your account.

Re: Ask HN: Gmail account security

#767
post #296

Hit this over XMas. Dad got a new fire stick. Wanted to use the YouTube app. Wanted to sign in to YouTube for channel subscriptions. Had a GMail account he'd not used in years. Tried to recover it with the whole send-a-code-to-secondary-email rigmarole. Google went to the trouble of sending a code, but upon successful entry decided that it just wasn't good enough. Maddening. Gmail account gone forever. Can't sign up…

I recommend NewPipe for watching YouTube on phone. Best of its kind, free and open-source. https://newpipe.net/

Re: Ask HN: Gmail account security

#768

Earlier quoted context omitted.

You might also like promnesia https://github.com/karlicoss/promnesia#readme And if you're interested we have a small discord server "awesome knowledge management" come join us! https://discord.gg/XPNeDSQE2j

What makes your discord server unique among the thousands of other knowledge-management organizations out there?

Nothing ¯\_(ツ)_/¯

Although you say "organization"... this isn't centered around a particular tool or anything.

I made it in response to a post about Promnesia on "Who wants to collaborate" https://news.ycombinator.com/item?id=29764928

Re: Ask HN: Gmail account security

#769
post #213

Earlier quoted context omitted.

Yes. The public good derived from sane EHR interoperability would be enormous. Lower costs, better treatments, more informed policies... But there are lots of political barriers. NHS is trying, and pretty open to private tenders. I'm actually working on a very related field. Smaller or more atomized healthcare systems than NHS would be probably even difficult to deal with initially.

The trouble with this issue for the NHS is that UK governments have tried to give away access to the most sensitive of records on a national scale so many times now and then rowed back in the face of predictable criticisms that the public would have to be collectively insane to allow broad access to medical records through any centralised system any time soon. It is unfortunate because obviously in principle a single…

> ...insane to allow broad access to medical records through any centralised system any time soon.

> It is unfortunate because obviously in principle a single centrally-administered records facility with robust security and audit trails for all access and a Hippocratic Oath level of privacy protections would be far better than the status quo in many ways.

Funny, one would have thought that pretty much is the status quo already: Looks to me like the UK already has (or should have) a single centrally-administered records facility with robust security and audit trails -- isn't that the NHS?

If it doesn't at the moment quite fulfill your requirements, it certainly ought to anyway, oughtn't it? So the problem is one of fixing its possible current deficiencies, not one of lacking it entirely. Or?

Re: Ask HN: Gmail account security

#770

Earlier quoted context omitted.

The trouble with this issue for the NHS is that UK governments have tried to give away access to the most sensitive of records on a national scale so many times now and then rowed back in the face of predictable criticisms that the public would have to be collectively insane to allow broad access to medical records through any centralised system any time soon. It is unfortunate because obviously in principle a single…

> ...insane to allow broad access to medical records through any centralised system any time soon. > It is unfortunate because obviously in principle a single centrally-administered records facility with robust security and audit trails for all access and a Hippocratic Oath level of privacy protections would be far better than the status quo in many ways. Funny, one would have thought that pretty much is the status q…

The NHS isn't really a single body at all. It's a vast, unimaginably complicated network of healthcare professionals, medical facilities, managerial organisations, supply chains, and so on, under the shared banner of being public-run and with strategic leadership appointed by the central government (modulo some devolution to different parts of the UK at various scales).

In normal circumstances an individual's primary point of contact with the NHS is supposed to be their GP, and the GP's surgery will normally hold the main medical records for each person under their care. But then other parts of the NHS, such as hospitals or therapists, may hold their own records in connection with the specialised treatments they provide. There are all kinds of protocols for sharing health records between clinical professionals who are directly responsible for a patient's care and potentially others and successive governments keep meddling with them in ways that make you nervous about those others and what they get to know and what they can do with it.

Post reply on HN