Live data from Hacker News

Ask HN: Gmail account security

news.ycombinator.com

21–30 of 807 posts

Re: Ask HN: Gmail account security

#21
post #7

Wasn't aware of this, but can't say I'm surprised. Personally, I'm still happy with Fastmail, which uses customer subscriptions fees to fund a professional support department, as well as contributing to email-related FOSS. (Among other things, obviously.)

Do they offer an api?

Re: Ask HN: Gmail account security

#22
post #7

Wasn't aware of this, but can't say I'm surprised. Personally, I'm still happy with Fastmail, which uses customer subscriptions fees to fund a professional support department, as well as contributing to email-related FOSS. (Among other things, obviously.)

Have you used Fastmail's support?

Re: Ask HN: Gmail account security

#23
post #11

So in theory if someone was to ever accidentally or intentionally reset the location info for where all gmail accounts have logged in from, then effectively everyone would be unable to access their gmail account?

If that were to happen it would take about 5 minutes until this security feature would be deactivated.

Re: Ask HN: Gmail account security

#24
post #21
post #7

Wasn't aware of this, but can't say I'm surprised. Personally, I'm still happy with Fastmail, which uses customer subscriptions fees to fund a professional support department, as well as contributing to email-related FOSS. (Among other things, obviously.)

Do they offer an api?

yes, and it makes the gmail API look like a toy

https://fastmail.blog/open-technologies/jmap-new-email-open-...

Re: Ask HN: Gmail account security

#26
Once again this shows that we're at the mercy of the giant AI machine. For fear of having my data locked into Google, I migrated to my own domain and e-mail hosting elsewhere. I'm still at the mercy of the hosting and domain registrar at that point, but at least they have phone numbers I can call to get support and talk to a human.

Offline backups is a must at this point.

Re: Ask HN: Gmail account security

#27

Had this. It was telling me to try again 'later'. Ok, i did 'try later' every day for three weeks, and they didn't let me in. Using the very same IP address as I used to always access it, no less. Then, I gave up, moved all my services to another email account, and after 2 or 3 months tried logging in, and it suddenly allowed me to log in. Needless to say, I will never again use gmail for critically important things.

> Needless to say, I will never again use gmail for critically important things.

That's a hot take. If it was critically important, you'd have 2FA and a recovery phone number associated with it - which would have prevented you from getting stuck in a trust-fail situation to begin with.

Use whatever service you want, but your takeaway from this situation is a bit absurd.

Edit to add: I'm not saying Google's algorithm is perfect here, but relying on heuristic voodoo ("I use the same IP, so I should be fine") for "critically important things" instead of using well-established means of securing access to critically important things (e.g. 2FA, backup mobile number) is a bit insane.

Re: Ask HN: Gmail account security

#28
It's especially annoying that you can't turn this nonsense off. I had this happen to me when I was abroad, obviously with no way to recover when I was abroad and I needed access to certain mails. Nice feature.

Re: Ask HN: Gmail account security

#29
post #17

I'm having a hard time getting my head wrapped around the idea of relying on Gmail (or any other online identity provider) without enabling 2-factor authentication. The best way to avoid this kind of "AI hell" is just to take control of your own account security and set up some additional factors.

Recently i wanted to setup a shared gmail account with some people.

Even with 2FA setup, correct password correct TOTP, it did not let them in because it was suspicious. I also checked "it was me" in all their security alerts. It would only let the person in with sms based 2fa, which was a pain.

Re: Ask HN: Gmail account security

#30
post #7

Wasn't aware of this, but can't say I'm surprised. Personally, I'm still happy with Fastmail, which uses customer subscriptions fees to fund a professional support department, as well as contributing to email-related FOSS. (Among other things, obviously.)

Fastmail's UI is just faster too.

I actually enjoy watching it tender at light speed!
Post reply on HN