Live data from Hacker News

Ask HN: Gmail account security

news.ycombinator.com

791–800 of 807 posts

Re: Ask HN: Gmail account security

#791

Earlier quoted context omitted.

(edited) If you don't mind sharing, what is the bug? - My comment originally read as follows, 2 people downvoted it. >I work at Google and recently tried to file a bug about the calculator embedded in search. It was dastardly difficult to find how to file the ticket. It took me maybe an hour. A better system for filing tickets internally and for filing and triaging tickets from external users would be a tremendous as…

You just found a bug in Google Calculator. You wrote "calories" but Google is giving you the answer in "kilocalories". If you change "calories" to "kilocalories" the answer doesn't change. I wonder how many times in the past has it given you the wrong answer without you noticing?

I tired 1000 millicalories, but doesn't look like Google understands that either.

Re: Ask HN: Gmail account security

#792

Earlier quoted context omitted.

"With Google’s nonexistent customer service..." What's needed is enough of these cases to bring a class action against Google. It's over a decade since I've used a Google account and I was similarly ignored even back then.

I have a few thousand dollars I earned with Adsense a bunch of years ago. They suspended my account and prevented me from getting the money. Every now and then I get a letter from some auditor that says I can claim the money. Just need to login to my google account. Needless to say google customer service hasn’t helped. Definitely need some class action suits to change their behavior, and I hate class action suits.

Exactly. But don't hold your breath waiting.

Re: Ask HN: Gmail account security

#793
post #780

Earlier quoted context omitted.

> Obviously this is well established in the insurance and finance industries, but make no mistake, it happens everywhere. Speaking from someone in the US--in both insurance and finance I can get a person on the phone to resolve my issue. Specific to finance, there are a number of consumer laws that protect me. If I'm denied credit based on my credit history, I'm allowed to know why. If my credit score is not accurate…

> Stripe, Amazon, Apple, to name three all have great support. True, but they have actual customers. As a user of Gmail, I can hardly be considered a customer. Google ads has customers though. Their support probably isn't great either, but does it need to be? Where else are you gonna go?

> Google ads has customers though. Their support probably isn't great either, but does it need to be? Where else are you gonna go?

I've not dealt with Google Ad support, but I can say from experience Facebook Ad's customer support is terrible.

Similar to Google, I'd speculate that the majority of customers pay such small amounts, that it's more cost effective for Google and Facebook to not support them, than it is to support them.

I would also speculate, that if you were instead, say Pepsi-Co, you would have white-glove service from both tech giants.

Re: Ask HN: Gmail account security

#794

Earlier quoted context omitted.

I guess this is why Amazon is playing the long game with their obsessive focus on customers. I don't know how that really plays out where the rubber meets the road but that's what Jeff bezos always keeps talking about.

I worked at both Amazon and Google. It was only at Amazon where I was exposed to the Craft of software development. Personally, I feel there is a nuanced difference to the role at Amazon being SDE ( Software Development Engineer ) whereas Google is SWE ( Software Engineer ). It's almost like Google thinks Software Developers are lower tier than Software Engineers, but I'd like to think of myself as doing more than ju…

[deleted]

Re: Ask HN: Gmail account security

#795

Earlier quoted context omitted.

I have several YubiKeys linked to my account. It will decline those as well. It demands that I sign in from Android sometimes, seemingly for no reason.

That's especially weird. I've had Google decline TOTP/Google Authenticator and SMS one time when I was troubleshooting a OAuth issue, but declining U2F? Are you logging in from various different VPN servers daily, or just through the same few ISPs?

No VPNs, just my home network with an IP address that rarely changes. What seems to throw it off is when I log in from "conflicting" platforms, particularly iOS + Android. I also have multiple iPhones for work, and it very much dislikes that.

When it gets in this state, nothing will work besides going to g.co/sc on Android--it can't be any other platform, regardless of how long I've had the device--and approving the code request there. If I approve it from any other device, even with a YubiKey, it'll give me a code on g.co/sc, but I'll be told it's invalid and I'll get one of those emails telling me the code was correct but declined due to suspicious activity.

I appreciate the attention to security, but c'mon, it's a YubiKey, and I'm logging in from my usual residential location.

Re: Ask HN: Gmail account security

#796
post #606

Earlier quoted context omitted.

I make a habit of 1. Forwarding everything to my free tier google apps for business on my domain 2. Annually logging into my throwaways. it seems if i login to them once a year from home, they dont pull this. 3. do NOT attempt to login to my throwaways from a proxies connection (SSH/SOCKS on a VPS or something like that, which i frequently use at work)

> my free tier google apps for business on my domain your habits are going to have to change soon...

Yeah....its unfortunate.

Currently I may just pay the cost. Or move to a more privacy focused service like ProtonMail and at least give my money to a place I support.

Re: Ask HN: Gmail account security

#797

Earlier quoted context omitted.

This [1] Neat fact, Google is yet to tell me they are making this change to my account. [1] https://arstechnica.com/gadgets/2022/01/google-tells-free-g-...

Yeah, I haven't gotten the official notification yet either. Maybe going in waves?

Not that anyone will likely see this, but I just now finally got my notice from Google about this change.

Re: Ask HN: Gmail account security

#798
post #780

Earlier quoted context omitted.

> Stripe, Amazon, Apple, to name three all have great support. True, but they have actual customers. As a user of Gmail, I can hardly be considered a customer. Google ads has customers though. Their support probably isn't great either, but does it need to be? Where else are you gonna go?

> Google ads has customers though. Their support probably isn't great either, but does it need to be? Where else are you gonna go? I've not dealt with Google Ad support, but I can say from experience Facebook Ad's customer support is terrible. Similar to Google, I'd speculate that the majority of customers pay such small amounts, that it's more cost effective for Google and Facebook to not support them, than it is to…

> Similar to Google, I'd speculate that the majority of customers pay such small amounts, that it's more cost effective for Google and Facebook to not support them, than it is to support them.

That's probably how they reason about it but I think it's a cultural thing too (pure tech Co's have a bias towards automation for everything, and a reluctance to staff operations at all). Amazon for instance has many low value customers, yet has much better support across the board.

> I would also speculate, that if you were instead, say Pepsi-Co, you would have white-glove service from both tech giants.

Oh absolutely, that's no secret. I know account managers that had a single big customer at one of these companies. It's part of the sales org basically.

Re: Ask HN: Gmail account security

#799

Earlier quoted context omitted.

I disagree with OP on this. Their boss in my opinion made the right call. I'd say for a few reasons: 1. Why did OP do this without talking through it first 2. Introducing a new language to a team is not some small decision, and IMO typically not a good idea 3. Why would it take a month in Java to do what takes a few days in Go 4. If it made this one task faster, the burden it will put on the team in the future can be…

> Their boss in my opinion made the right call. I'd say for a few reasons: Well you don't have enough context to say it was the right call. > 1. Why did OP do this without talking through it first I was tasked to prototype / MVP / "tracer dart" and prove that it was feasible. As proven, it took 2 days in Go. If it was done with Unix commands, the pieces can be jumbled together in a day. The point was having a self-co…

Thanks for adding more context.

You do seem to be making assumptions and having expectations on how the team and how Google should operate. Regarding Java, I don't find the claims that Java isn't as good as Go compelling. For you, sure, but to make general claims is silly. There are many successful companies and productive developers using Java.

There are probably companies that are very productive in how you would want to pick and choose languages based on the problem. IMO, the language choice is not all that important, though I do think PHP, JavaScript, and similarly poorly designed languages are probably a hinderance (but again there are many successful companies using these like you said, so I think that's convincing that the language doesn't really matter all that much).

Re: Ask HN: Gmail account security

#800
post #744
post #453

Earlier quoted context omitted.

All hardware dies at some point. What if both the Yubikeys die? What if the third one was already dead before and it wasn’t noticed because it wasn’t used recently? This sounds like too deep a maze for I don’t know how much benefit.

It’s really up to the user to determine whether it’s worth it for them. I work in security, so I eat my own caviar in my personal set up and like to test things out. All hardware dies, but I also have different keys from different vendors (not just yubico), purchased at different times. The likelihood that all 3 die at the same time is very low. Whether it prevents an attack that would be successful without the physi…

> But to have this level of security requires extra work, and part of that work is regularly testing that the keys still work.

This is a late reply, but thanks for your detailed response. I agree that this requires extra work, and that it is important. But the cost of multiple hardware keys also add up. So I doubt if this is a solution for the masses (of course, I'm not implying that anyone who's concerned about losing an account shouldn't spend some money and time).

If you do see this reply, I'd like to know the other vendors (apart from Yubico) whose keys you use.

Post reply on HN