Anti-patterns in registration are annoying too. A recent example from Twitter: "sign up with phone or email" (defaults to phone); click email (colleague insists on only using phone for work); register with email only. 2 minutes later: "give us your phone number to unlock your account." Crazy.
Ask HN: Gmail account security
81–90 of 807 posts
Re: Ask HN: Gmail account security
#82Had this. It was telling me to try again 'later'. Ok, i did 'try later' every day for three weeks, and they didn't let me in. Using the very same IP address as I used to always access it, no less. Then, I gave up, moved all my services to another email account, and after 2 or 3 months tried logging in, and it suddenly allowed me to log in. Needless to say, I will never again use gmail for critically important things.
> Needless to say, I will never again use gmail for critically important things. That's a hot take. If it was critically important, you'd have 2FA and a recovery phone number associated with it - which would have prevented you from getting stuck in a trust-fail situation to begin with. Use whatever service you want, but your takeaway from this situation is a bit absurd. Edit to add: I'm not saying Google's algorithm…
Re: Ask HN: Gmail account security
#83Re: Ask HN: Gmail account security
#84Re: Ask HN: Gmail account security
#85A couple hours later my account was blocked due to "suspicious login(s)" (i.e. mine), and the order I placed cancelled. They had me wait 24h until I could contact someone at support that could unblock it. He told he was going to disable 2FA (?) and send me a code that I could use to change my password.
The code was sent via SMS.
They think that someone who has just my SIM card (or a clone, FFS) is more trustworthy than someone who has my password, 2FA token, and email address.
These companies take user security as a joke, or as pure theater.
Re: Ask HN: Gmail account security
#86My main account gave me a similar message to yours; the only option was to approve this location via a link sent to my "nominated backup email".
Which, also refused to let me in for exactly the same reason. *facepalm*
Re: Ask HN: Gmail account security
#87Earlier quoted context omitted.
> Needless to say, I will never again use gmail for critically important things. That's a hot take. If it was critically important, you'd have 2FA and a recovery phone number associated with it - which would have prevented you from getting stuck in a trust-fail situation to begin with. Use whatever service you want, but your takeaway from this situation is a bit absurd. Edit to add: I'm not saying Google's algorithm…
I have 2FA and a recovery email on my Gmail account, yet I have run into this issue. If Google thinks something is suspicious, it will decline your 2FA codes and recovery attempts—it will just tell you that you entered the wrong code. Only after you finally get back in do you find an email in your inbox explaining that the correct code was entered, but Google blocked it because it was suspicious. This happens to me f…
Re: Ask HN: Gmail account security
#88try user agent modification, it claims all this crap about wanting a device you signed in to before but in my humble experience using Linux + Firefox, all is fixed if I switch my user agent so it appears I am using Windows + Edge.
Re: Ask HN: Gmail account security
#89Re: Ask HN: Gmail account security
#90Reailize that what you call "security" isn't there to protect you. It protects Google's interests. Google wants to minimize the risk of hackers compromising any google service; and if doing so might destroy your livelihood, well, that's a risk Google is willing to take.