Live data from Hacker News

Ask HN: Gmail account security

news.ycombinator.com

71–80 of 807 posts

Re: Ask HN: Gmail account security

#71
I feel your pain. You’ll probably have better luck logging in if you add a hardware token or 2fa. most android phones have a built in hardware token, or you can buy a yubikey or the tokens from google (often on sale for $5)

Re: Ask HN: Gmail account security

#72
post #16

That doesn't help OP now, but I found it helpful to enable 2FA with Google Authenticator, and keep emergency backup codes in a safe place. It's slightly more hassle, but there are less 'soft AI' barriers between you and your successful login. I'd also suggest not to rely on a phone number as 2nd factor, it's not that super safe.

I’d recommend a non-Google 2FA app. Microsoft has one, and Authy is popular. Personally I’m happy with OTP Auth. Some password managers can also handle 2FA, e.g. Strongbox.

Any particular reason?

Re: Ask HN: Gmail account security

#73
post #7

Wasn't aware of this, but can't say I'm surprised. Personally, I'm still happy with Fastmail, which uses customer subscriptions fees to fund a professional support department, as well as contributing to email-related FOSS. (Among other things, obviously.)

Fastmail looks great, but having "Get the email features you need, without giving up your privacy" and "Your data is always private" at the top of their homepage while knowing full well that is far from the case[0,1] seems disingenuous.

[0] FastMail loses customers, faces calls to move over anti-encryption laws https://www.itnews.com.au/news/fastmail-loses-customers-face...

[1] Goodbye FastMail https://www.ctrl.blog/entry/goodbye-fastmail.html

Re: Ask HN: Gmail account security

#74
post #53

Earlier quoted context omitted.

Can I ask which news? I'm already a happy Fastmail customer, just curious.

This [1] Neat fact, Google is yet to tell me they are making this change to my account. [1] https://arstechnica.com/gadgets/2022/01/google-tells-free-g-...

Yeah, I haven't gotten the official notification yet either. Maybe going in waves?

Re: Ask HN: Gmail account security

#75
Immediate solution to try: Use a mail client to access your mailbox with IMAP or POP3; GMail may be more tolerant that way.

Long-term solution: Stop using Google. Why? Not just because of this type of shenanigans, but because Google spies on you:

* It keeps a copy of all of your correspondence, even if you delete it.

* (Rephrased) The US National Security Agency (NSA) has gotten access to much of your correspondence, by tapping links between Google's data center; it may still have such access today and Google's extent of collaboration with this is not known for certain (to me anyway).

* It uses your correspondence and other information about you allow commercial companies to manipulate you with advertisement.

(The NSA part was verified by Edward Snowden's revelations, several years back; see: https://www.washingtonpost.com/world/national-security/nsa-i... for example)

Now, no third-party mail service is perfectly safe; but you should want one which is at least somewhat-safe, and that doesn't treat you unfairly.

I won't make specific recommendations, but I've personally had decent experience with ProtonMail (Switzerland) and gmx.com (Germany).

Re: Ask HN: Gmail account security

#76
post #16

That doesn't help OP now, but I found it helpful to enable 2FA with Google Authenticator, and keep emergency backup codes in a safe place. It's slightly more hassle, but there are less 'soft AI' barriers between you and your successful login. I'd also suggest not to rely on a phone number as 2nd factor, it's not that super safe.

I’d recommend a non-Google 2FA app. Microsoft has one, and Authy is popular. Personally I’m happy with OTP Auth. Some password managers can also handle 2FA, e.g. Strongbox.

I'd recommend andOTP here as it is open source and not tied to any company that's trying to sell you anything.

Re: Ask HN: Gmail account security

#77
post #27

Had this. It was telling me to try again 'later'. Ok, i did 'try later' every day for three weeks, and they didn't let me in. Using the very same IP address as I used to always access it, no less. Then, I gave up, moved all my services to another email account, and after 2 or 3 months tried logging in, and it suddenly allowed me to log in. Needless to say, I will never again use gmail for critically important things.

> Needless to say, I will never again use gmail for critically important things. That's a hot take. If it was critically important, you'd have 2FA and a recovery phone number associated with it - which would have prevented you from getting stuck in a trust-fail situation to begin with. Use whatever service you want, but your takeaway from this situation is a bit absurd. Edit to add: I'm not saying Google's algorithm…

I have 2FA and a recovery email on my Gmail account, yet I have run into this issue. If Google thinks something is suspicious, it will decline your 2FA codes and recovery attempts—it will just tell you that you entered the wrong code. Only after you finally get back in do you find an email in your inbox explaining that the correct code was entered, but Google blocked it because it was suspicious.

This happens to me from time to time, and the only way I can get back in is through Android. I keep an Android phone on hand at all times for this very reason.

Don’t blame the human for inadequate preparation; I assure you, no amount of preparation will save you from Google’s AI.

Re: Ask HN: Gmail account security

#78
post #27

Earlier quoted context omitted.

> Needless to say, I will never again use gmail for critically important things. That's a hot take. If it was critically important, you'd have 2FA and a recovery phone number associated with it - which would have prevented you from getting stuck in a trust-fail situation to begin with. Use whatever service you want, but your takeaway from this situation is a bit absurd. Edit to add: I'm not saying Google's algorithm…

Something can be critically important for a person to access on-demand and not be something they’re especially concerned about an attacker accessing. Two completely unrelated dimensions of access needs.

They are not mutually exclusive. An attacker accessing a service can hinder or even completely stop your ability to access that service (i.e. change your password).

Re: Ask HN: Gmail account security

#79
This is because most people use Gmail for basically all their online accounts: if you don't directly login to the site via Gmail, you can use your account to change your password. Imagine the damage which can be done if a malicious user breaks into someone's Gmail, if not your own, then the average person who uses the same password everywhere and trusts Gmail with everything.

Not defending the practice at all. It shows we as a society and Google in particular need better security if they are flat-out locking people out of their Gmail accounts and others are still being compromised (I know they are). I honestly support Google forcing people to use recovery addresses and 2-factor authentication but I don't support them making the recovery authentication not work and providing literally no options for a legitimate user.

I think the best you can do right now is complain on HN and Twitter and you'll probably get your account back. In the future, maybe if you have a YubiKey or stronger form of 2FA Google won't lock you out, because obviously if someone can authenticate with a YubiKey they are practically guaranteed to be the real person.

Post reply on HN