Live data from Hacker News

Ask HN: Gmail account security

news.ycombinator.com

81–90 of 807 posts

Re: Ask HN: Gmail account security

#81
I stopped using it too. The email service isn't that great (minimizing email in general), Google can be a pain to use for reasons already mentioned, and at the time there was a small swing against surveillance capitalism.

Anti-patterns in registration are annoying too. A recent example from Twitter: "sign up with phone or email" (defaults to phone); click email (colleague insists on only using phone for work); register with email only. 2 minutes later: "give us your phone number to unlock your account." Crazy.

Re: Ask HN: Gmail account security

#82
post #27

Had this. It was telling me to try again 'later'. Ok, i did 'try later' every day for three weeks, and they didn't let me in. Using the very same IP address as I used to always access it, no less. Then, I gave up, moved all my services to another email account, and after 2 or 3 months tried logging in, and it suddenly allowed me to log in. Needless to say, I will never again use gmail for critically important things.

> Needless to say, I will never again use gmail for critically important things. That's a hot take. If it was critically important, you'd have 2FA and a recovery phone number associated with it - which would have prevented you from getting stuck in a trust-fail situation to begin with. Use whatever service you want, but your takeaway from this situation is a bit absurd. Edit to add: I'm not saying Google's algorithm…

I do wonder how many people will be locked out of their lives when they change phone numbers. 2FA across the industry seems to have rolled out this critical dependency without drawing enough (IMHO) awareness.

Re: Ask HN: Gmail account security

#83

Earlier quoted context omitted.

Have you used Fastmail's support?

Yes. It’s great!

Good to hear. I’ve been with them for a few years and support was one of the reasons I moved over from Gmail but I’ve never actually needed it.

Re: Ask HN: Gmail account security

#85
One day I logged in to my Amazon account from a different country. Mind you, I have 2FA/OTP enabled in my account, and I entered it correctly. They also made me click on a link they sent via email to "verify my login".

A couple hours later my account was blocked due to "suspicious login(s)" (i.e. mine), and the order I placed cancelled. They had me wait 24h until I could contact someone at support that could unblock it. He told he was going to disable 2FA (?) and send me a code that I could use to change my password.

The code was sent via SMS.

They think that someone who has just my SIM card (or a clone, FFS) is more trustworthy than someone who has my password, 2FA token, and email address.

These companies take user security as a joke, or as pure theater.

Re: Ask HN: Gmail account security

#86
I had a similar issue with outlook when I went to visit my parents in Cyprus (normally I live in the UK)

My main account gave me a similar message to yours; the only option was to approve this location via a link sent to my "nominated backup email".

Which, also refused to let me in for exactly the same reason. *facepalm*

Re: Ask HN: Gmail account security

#87
post #77
post #27

Earlier quoted context omitted.

> Needless to say, I will never again use gmail for critically important things. That's a hot take. If it was critically important, you'd have 2FA and a recovery phone number associated with it - which would have prevented you from getting stuck in a trust-fail situation to begin with. Use whatever service you want, but your takeaway from this situation is a bit absurd. Edit to add: I'm not saying Google's algorithm…

I have 2FA and a recovery email on my Gmail account, yet I have run into this issue. If Google thinks something is suspicious, it will decline your 2FA codes and recovery attempts—it will just tell you that you entered the wrong code. Only after you finally get back in do you find an email in your inbox explaining that the correct code was entered, but Google blocked it because it was suspicious. This happens to me f…

Microsoft & Zoho Mail does the same, and when they do it, they also revoke all of your app specific password for good measure, so SMTP is a toast too.

Re: Ask HN: Gmail account security

#88

try user agent modification, it claims all this crap about wanting a device you signed in to before but in my humble experience using Linux + Firefox, all is fixed if I switch my user agent so it appears I am using Windows + Edge.

though this and the fact gmail manages to hide my important emails, I moved to using Zoho, which stays out of my way and plays nice with neomutt

Re: Ask HN: Gmail account security

#90
You get what you pay for. Microsoft hotmail is pretty much the same.

Reailize that what you call "security" isn't there to protect you. It protects Google's interests. Google wants to minimize the risk of hackers compromising any google service; and if doing so might destroy your livelihood, well, that's a risk Google is willing to take.

Post reply on HN