Live data from Hacker News

Ask HN: Gmail account security

news.ycombinator.com

31–40 of 807 posts

Re: Ask HN: Gmail account security

#31
post #11

So in theory if someone was to ever accidentally or intentionally reset the location info for where all gmail accounts have logged in from, then effectively everyone would be unable to access their gmail account?

Worse, one day it just doesn't work.

Re: Ask HN: Gmail account security

#32
post #20
post #17

I'm having a hard time getting my head wrapped around the idea of relying on Gmail (or any other online identity provider) without enabling 2-factor authentication. The best way to avoid this kind of "AI hell" is just to take control of your own account security and set up some additional factors.

Google will still lock you out with 2fa. It’s pretty bad

Even with a FIDO2/U2F/WebAuthn key?

If so, yeah that's pretty bad..

Re: Ask HN: Gmail account security

#33
post #17

I'm having a hard time getting my head wrapped around the idea of relying on Gmail (or any other online identity provider) without enabling 2-factor authentication. The best way to avoid this kind of "AI hell" is just to take control of your own account security and set up some additional factors.

Except Google does not honor the recovery account. Even with access to the recovery code, Gmail just ignores it.

Re: Ask HN: Gmail account security

#34
post #7

Wasn't aware of this, but can't say I'm surprised. Personally, I'm still happy with Fastmail, which uses customer subscriptions fees to fund a professional support department, as well as contributing to email-related FOSS. (Among other things, obviously.)

Last week's news gave a lot of people the nudge they needed to finally migrate away from their legacy free GSuite accounts to something more reliable.

Re: Ask HN: Gmail account security

#35
Some similar thing happen to me. Gmail login page says that I need to acknowledge that me is me and it forces me to change password... I occasionally get this message on screen when I change countries with VPN. I need to use VPN different countries because this is required by my work (development of streaming services). I get so much annoyed. Recently I spent Christmas in Norway (not the country of my origin) and that happened again. I had to access Gmail to check in the flight so I was forced to change the password. This is ridiculous!

Re: Ask HN: Gmail account security

#36
post #7

Wasn't aware of this, but can't say I'm surprised. Personally, I'm still happy with Fastmail, which uses customer subscriptions fees to fund a professional support department, as well as contributing to email-related FOSS. (Among other things, obviously.)

I'm also a happy customer of Fastmail. Can recommend.

Re: Ask HN: Gmail account security

#37
If there is one Google service I'd happily pay 10 bucks a month for (given that they would then provide proper support), it'd be gmail.... It'd be a nightmare for any gmail user when suddenly their account is blocked for no particular reason. This post is reminding me to look for alternatives.

Re: Ask HN: Gmail account security

#38
post #27

Had this. It was telling me to try again 'later'. Ok, i did 'try later' every day for three weeks, and they didn't let me in. Using the very same IP address as I used to always access it, no less. Then, I gave up, moved all my services to another email account, and after 2 or 3 months tried logging in, and it suddenly allowed me to log in. Needless to say, I will never again use gmail for critically important things.

> Needless to say, I will never again use gmail for critically important things. That's a hot take. If it was critically important, you'd have 2FA and a recovery phone number associated with it - which would have prevented you from getting stuck in a trust-fail situation to begin with. Use whatever service you want, but your takeaway from this situation is a bit absurd. Edit to add: I'm not saying Google's algorithm…

Something can be critically important for a person to access on-demand and not be something they’re especially concerned about an attacker accessing. Two completely unrelated dimensions of access needs.

Re: Ask HN: Gmail account security

#40
post #27

Had this. It was telling me to try again 'later'. Ok, i did 'try later' every day for three weeks, and they didn't let me in. Using the very same IP address as I used to always access it, no less. Then, I gave up, moved all my services to another email account, and after 2 or 3 months tried logging in, and it suddenly allowed me to log in. Needless to say, I will never again use gmail for critically important things.

> Needless to say, I will never again use gmail for critically important things. That's a hot take. If it was critically important, you'd have 2FA and a recovery phone number associated with it - which would have prevented you from getting stuck in a trust-fail situation to begin with. Use whatever service you want, but your takeaway from this situation is a bit absurd. Edit to add: I'm not saying Google's algorithm…

With Google’s nonexistent customer service I’d be afraid of being locked out for any arbitrary reason and having no recourse no matter what recovery procedures I prepared for.

Contrast that to my bank where I can go to the branch, show ID, and get problems logging in resolved.

Post reply on HN