Live data from Hacker News

Don’t Mess with The Google

dansdeals.com

301–310 of 504 posts

Re: Don’t Mess with The Google

#301

Disclaimer: I don't speak for Google and don't have any real context into why this occurred. Speaking as myself, a private citizen. I work in Spam & Abuse and it's possible that this is the result of some clustering algorithm that was trying to take down sharders / phone buying rings. It's very possible that the SWEs responsible didn't consider this possibility (that legitimate customers would be used to shard purcha…

Hopefully you haven't given up on reading the comments to your post and you see this. Small practical suggestion, no flames.

It might be a very very good idea to lobby to get company policy instated that says "if the system thinks a user has gone rogue/bad, their account gets locked and all, but the data gets kept around until the user says to kill it, or for 6 months."

Because if Google thinks the account has gone bad, that's not the user saying "delete me," so the privacy policy (and associated laws) don't apply! There's nothing stopping you even stashing the data away indefinitely until the user explicitly asks for it to be killed (but that's scary).

At the end of the day though, algorithms fail, and IMO this is a practical edge-case policy glitch in the business architecture that should have been countered for.

Or does "user account gone rogue" have to be interpreted as "delete me" for crazy obscure Reasons™?

Re: Don’t Mess with The Google

#302
post #178
post #100

Earlier quoted context omitted.

I might have to switch at some point. It is stories like these that are freaking me out. Were there any instances of them being DoS-ed or you not getting emails from others? I would also be afraid one day if Google sees people fleeing to them, they'd come in and buy them. I'd almost whish there was a public trust or non-profit who would run an email server. Post office is a government service (for better or for worse…

ime: their spam detection is definitely inferior to gmail; I've had 2-5 false negatives per month (spam not detected) and a handful of false positives over 3+ years. Plus a payment notice from my student loan that fastmail absolutely positively refuses to believe is not spam not matter how many times I so mark it. I've had zero deliverability issues. edit: to be clear, the spam detection works well, and if you're goi…

"a payment notice from my student loan that fastmail absolutely positively refuses to believe is not spam"

That's because it's not spam. I'm pretty sure there's a blog post coming soon about the difference between spam and "email I don't want to receive". If you just don't want to hear from a particular email address, the way to stop it is to put an explicit discard rule for that address in your Rules screen.

Likely changes for next year include making a much easier UI option for "don't show me email from this address again", because that's a fairly common request for situations like this where you have a vexatious sender. I suspect it will be implemented as an addressbook group - the anti-whitelist!

Re: Don’t Mess with The Google

#303
post #297

Earlier quoted context omitted.

That is why I stick to OSS like Linux, Thunderbird, nextcloud, etc. as much as possible. I got locked into a closed source platform once and it was a pain to get out of it. I will never let it happen again.

Self storage is fine but does it guaranty long term documents safety? I am very sceptical about my ability of maintaining it on the long term.

I have a home server, which is then mirrored to a rented server. Anything critical and entirely irreplaceable goes onto blu-ray disks, because I can't accidentally delete those; though those are kept at home as well, which is not ideal.

So: 2 backups, from which one is off-site and archives, just in case - this should keep you going for a while with self storage.

Re: Don’t Mess with The Google

#304
post #180

Earlier quoted context omitted.

Any modern phone should be able to run a TOTP client. For my own FastMail account I have a TOTP client on my phone plus two Yubikeys, one I carry with me and one that I keep at home. We require all our staff use 2FA because emails from us get the magic green tick :) So yeah, if I have my phone, I have a 2FA option already without SMS. I normally use the Yubikey because it's super easy.

How do you use a yubikey on your phone? Or did you mean in lieu of totp on your phone?

For Fastmail I plug it into the USB port as usual (using an OTG cable). Last I checked that was still the only way to do it specifically for Fastmail, since they do not support NFC. For Lastpass though, using the Yubikey through NFC works great.

Re: Don’t Mess with The Google

#305
post #266

Earlier quoted context omitted.

Wait until they get into the thought police business for some real interesting situations. All jokes aside, for those who remember, it's pretty amazing what Microsoft got punished for ( bundling a browser with the OS, with no other restrictions) compared to what Apple and Google get away with.

Try this one http://craphound.com/scroogled.html by Doctorow.

Wow, the HTML for that page fell through a bit of a can opener there.

Also, I must frankly admit my great curiosity at the fact that your last comment was posted 3.61 years ago. Alt account? Deleted comments?

Re: Don’t Mess with The Google

#306

Earlier quoted context omitted.

That is why I stick to OSS like Linux, Thunderbird, nextcloud, etc. as much as possible. I got locked into a closed source platform once and it was a pain to get out of it. I will never let it happen again.

And for email ?

I'm myself using a non-profit email redirection service as my main e-mail address. They do not provide an email box, just the redirect, so they can keep the service lean with a very modest one-time fee for new members.

This allows me to change the actual e-mail provider when needed. I already moved (successfully) away from Gmail, and I'm currently considering moving again as the spam protection of my current paid-for email service isn't that great.

I think the redirection service is ingenious. Sadly it isn't available worldwide, so I won't advertise it here, but I'm sure there are others like that.

Re: Don’t Mess with The Google

#307
post #64

Earlier quoted context omitted.

Fastmail. I'm just a regular (paying) customer, not a business or anything. I've opened a small number of tickets, one or two of the RTFM variety. I've always got a human response and satisfaction, even a "here, let me RTFM that for you." I can't imagine being locked out of my fastmail account for anything other than abuse of my fastmail account . Or not paying my bill.

We also stalk you on... I mean, we read the same tech news sites you do. (I'm on third line ticket duty right now, so if you have something significantly more complex than RTFM, or an actual bug, you'll probably be talking to me this week) The most common cause of getting locked out other than you abusing your fastmail account is having your credentials stolen and used for spam/fraud, which is why we recommend 2 fact…

I've been w/ you guys since there was a 'bounce' function (miss that, btw). Used to use 2FA w/ a Yubikey, but stopped for some reason that made sense at the time, though I don't recall what happened, was so long ago.

What keeps me from enabling 2FA again, is that there's always some kind of "I lost my 2FA device" function which essentially allows it to be bypassed. So whoever's determined enough could find answers to secret questions or whatever to gain unauthorized access. If it were possible to disable this attack vector I'd get another Yubikey & try again- if...

...The other thing that prevents me from going this route, which is: The fact that it's impossible to implement an additional Yubikey functioning as a "clone" of the one used to secure the account. I can't say I've never lost my (physical) keys. But when I do I just grab my backup copies, make new backup copies, & all is well. No can do with a Yubikey.

-My 2c

Re: Don’t Mess with The Google

#308
post #257

Earlier quoted context omitted.

Going on a tangent, there should probably be a set of universal backup formats that can be advertised as being somewhat portable. So that, if you need to can take your mail and other online business stuff elsewhere if need be. Beyond this article a user might start working for some place that does not allow external app use, but they can bring their data with, to be loaded onto the service. I guess like github and gi…

For Email with IMAP, you have the wonderful offlineimap tool[0], I have been using it for years, you can easily perform a maildir format[1] backups of all your email accounts. [0]: http://www.offlineimap.org/ [1]: https://en.wikipedia.org/wiki/Maildir

I have been taking a Thunderbird local dump of all my Google mail for years as a backup (Thunderbird's mbox format is readable everywhere) so I can clear my Google account regularly, yet have a backup.

No idea what I'll do when Thunderbird eventually goes away - what is the replacement with identical functionality on macOS? I only want to grab mail and append to my existing mbox files.

Re: Don’t Mess with The Google

#309
post #217
post #170

First post, might as well be a cautionary tale. My father, a pretty old programmer by anyone's standards, regularly warns me of this sort of thing. He was pretty much shafted by CompuServe many years ago on a miniscule scale compared to what is possible now. He lives his life in what I previously described as a paranoid bubble of data control. Until I inevitably burned myself with Google. I have no idea what happened…

Backups! Even in the cloud era you still need backups.

This is not just about backups; this is the reason why I keep my mail on my own domain. ( It could by my own domain on gmail; it's not, but that a slightly different story ) This way I can move it to another company, alter DNS, do whatever I want with it to fix an issue.

When you're relying on a company you cannot circumvent in a situation like this (xyz@gmail.com as primary address), you might end up not being able to use your primary account, which might effect your business.

EDIT: I'm not going to address the problems with the DNS system itself, which is similarly flawed - you are only leasing a domain, not owning it, and the company maintaining it has the power over it. In theory, this could have been addressed with .onion IDs, but those are impossible to remember and with namecoin's .bit, bit this is not supported by enough real life DNS systems, so there is no alternative to that (yet).

Re: Don’t Mess with The Google

#310

Earlier quoted context omitted.

We (FastMail) are really nice people :)

Does FastMail have any equivalent to Inbox (reminders/snoozing emails)? I started to migrate last month, got lazy when I realized how much I used those, and then I think my trial account lapsed. This article might scare me enough into trying again anyway, but if I can find any replacement for reminders (Fastmail or otherwise) that's as nice to use I'll jump over so fast.

We don't have snooze yet, but it's getting really close. We have a plan for it which I started on nearly a year ago (Christmas day 2015!) and then it got mothballed behind other things - but we have a grand plan for how it would work, so it's a matter of some more internal plumbing.
Post reply on HN