Live data from Hacker News

JavaScript is now required to sign in to Google

security.googleblog.com

521–529 of 529 posts

Re: JavaScript is now required to sign in to Google

#521
post #517
post #515

Earlier quoted context omitted.

I just tried creating a new account from a VPN, using a browser that I haven't used to log into Google previously. It allowed me to create a new account without a backup phone or email, and allowed me to send an email. How does Google know you've hit a limit when you've registered new emails? And, not to belabor the point, but why should they be expected to give you unlimited number of free accounts -- or, what servi…

I mean they could accept my cash instead of offering a service paid for with your information. Oh that’s right, they’ll never give the consumer power over their data because that’s google’s entire value proposition.

So, don't use google, and run your own DNS that returns 0.0.0.0 for all google tlds. I mean, I'm all about having some responsibility at the corporate level, and people working for companies showing ethics.

But this is just cringe worthy. How do you propose getting your cash to said company? I mean, most methods will leak personal information the company could then use anyway.

Re: JavaScript is now required to sign in to Google

#522

Earlier quoted context omitted.

If a website is smaller it may not be sticky enough for a user to feel they get enough value to put in the effort to do 2FA

That's totally fair, but you don't have to force 2FA on your users.

For good and bad, I happen to like social media for logins... Twitter, fb, google, ms all offer them. In the end if you get their "real name" and email address, I find that generally sufficient. You don't have to do the actual authentication, users can configure 2fa on their own.

I mean, some site do ask for way more than they need here and that's often bad. In the end, I think it's a reasonable trade off for end-use convenience. Which I often am.

Re: JavaScript is now required to sign in to Google

#523

Earlier quoted context omitted.

FIY, IMAP actually allows "push messages" via the IDLE extension. If you use K9 on android, it's enabled by default. I never used gmail, but I'd be surprised if the gmail imap server didn't support it (and I would dismiss gmail entirely if it didn't).

Is this a new thing? I don't recall seeing an option for that in Thunderbird (desktop version by the way; not the mobile / Android version) the last time I looked (~9 months ago).

IDLE is an old extension. Unfortunately Thunderbird is a crappy client.

Re: JavaScript is now required to sign in to Google

#524

Earlier quoted context omitted.

Is this a new thing? I don't recall seeing an option for that in Thunderbird (desktop version by the way; not the mobile / Android version) the last time I looked (~9 months ago).

IDLE is an old extension. Unfortunately Thunderbird is a crappy client.

What would you recommend then?

I don't use Thunderbird myself - was just following the discussion on from the OP who did use it. However I've yet to find a client I like so genuinely interested in any suggestions you might have.

Re: JavaScript is now required to sign in to Google

#525

Earlier quoted context omitted.

IDLE is an old extension. Unfortunately Thunderbird is a crappy client.

What would you recommend then? I don't use Thunderbird myself - was just following the discussion on from the OP who did use it. However I've yet to find a client I like so genuinely interested in any suggestions you might have.

I'm currently using mutt with "getmail" (which does support IDLE), which I can recommend -- it's an excellent client, but only if you're fine with tweaking.

I used TB until two years ago, but I gave up with it's unfixed bugs and quirks. I do prefer graphical clients, but not if they are clunky or buggy.

I used Silpheed and Claws for years, but Silpheed locks (or used to lock) the UI during fetch (unacceptable IMHO) while Claws has some critical bugs in the filter/rule logic that made me lose mail in several occasions by refiling into the wrong folder while processing a lot of messages. If you arent't a heavy filter user you might be fine with it though, I think Claws gets a lot of things right.

KMail wasn't bad when I used it, but it was too long ago to make an honest comment today.

Re: JavaScript is now required to sign in to Google

#526
post #284
post #237

Earlier quoted context omitted.

That's the first obvious countermeasure and will prevent hackers targeting a specific account. But there are other ways to crack passwords, one is to try the same password but iterate over user ids instead. As hackers would start with the most common password you can't throttle globally on same password attempts either because well yeah, it is by definition the most commonly used one which should have a lot of traffi…

Google can ban common passwords, or passwords that look like they’re being targeted (over the long-run).

This has nothing to do with anything but I don't know how else to get in touch with you. Could you upload your zero spam email setup guide somewhere? Your site was hacked so the link I had doesn't work:

http://iamqasimk.com/2016/10/16/absolutely-zero-email-spam/

Re: JavaScript is now required to sign in to Google

#527
post #515

Earlier quoted context omitted.

I am surprised to see a long thread about nothing. Google does force you to give them your phone number and they do not let you register new emails after you hit some limit.

I just tried creating a new account from a VPN, using a browser that I haven't used to log into Google previously. It allowed me to create a new account without a backup phone or email, and allowed me to send an email. How does Google know you've hit a limit when you've registered new emails? And, not to belabor the point, but why should they be expected to give you unlimited number of free accounts -- or, what servi…

The moment you try to login from another location, they will lock you out and ask you to enter a phone number, which from that point forward will be tied to your account.

I am not 100% whether they use geolocation, or just trigger this when your new IP doesn't match the last IP you logged in with.

Re: JavaScript is now required to sign in to Google

#528

Earlier quoted context omitted.

Sorry, but at this point it is pretty obvious that big tech companies care about account security only as far as it impact their services. The late revelation about Facebook abusing 2FA phone numbers for marketing is a great demonstration of how that works. Google too does some really funny things to make it nearly impossible to create and maintain an anonymous accounts not tied to a phone number. Even when those acc…

> Pushing JavaScript everywhere increases the attack surface for every single user on the web. I understand where you're coming from, but most users browse the web with Javascript = on. Even as a NoScript user I have Google whitelisted because most of their services are unusable without Javascript. Even automated tools have good Javascript engines now thanks to headless mode in popular browsers. I suspect the next st…

I am not talking about merely enabling JavaScript. I am talking about normalizing more and more APIs accessible to every website I visit. Sound. Canvas. 3D. Local storage.

Re: JavaScript is now required to sign in to Google

#529
post #284

Earlier quoted context omitted.

Google can ban common passwords, or passwords that look like they’re being targeted (over the long-run).

This has nothing to do with anything but I don't know how else to get in touch with you. Could you upload your zero spam email setup guide somewhere? Your site was hacked so the link I had doesn't work: http://iamqasimk.com/2016/10/16/absolutely-zero-email-spam/

I’m sorry, I changed the domain to QasimK.io, but neglected to set up forwarding. I will do that.

http://qasimk.io/2016/absolutely-zero-email-spam/

Post reply on HN