Live data from Hacker News

Ask HN: Gmail account security

news.ycombinator.com

101–110 of 807 posts

Re: Ask HN: Gmail account security

#101

Immediate solution to try: Use a mail client to access your mailbox with IMAP or POP3; GMail may be more tolerant that way. Long-term solution: Stop using Google. Why? Not just because of this type of shenanigans, but because Google spies on you: * It keeps a copy of all of your correspondence, even if you delete it. * (Rephrased) The US National Security Agency (NSA) has gotten access to much of your correspondence,…

> It send the US National Security Agency (NSA) a copy of all of your correspondence

Google did no such thing. What Snowden revealed was that the NSA knew at that time the SSL connections from a user to Google were terminated at the GFE, and all the traffic between Google data centers were in cleartext. That includes, for example, a request from an application to store some user data in a database or storage system, or the replication between data centers of user data for redundancy purposes. NSA then wiretapped these communication links.

See this leaked NSA slide: https://commons.wikimedia.org/wiki/File:NSA_Muscular_Google_...

Re: Ask HN: Gmail account security

#102
post #53

Earlier quoted context omitted.

Last week's news gave a lot of people the nudge they needed to finally migrate away from their legacy free GSuite accounts to something more reliable.

Can I ask which news? I'm already a happy Fastmail customer, just curious.

There was an HN discussion about it here: https://news.ycombinator.com/item?id=29996432

People are pissed.

Re: Ask HN: Gmail account security

#103
Things I can recommend in your situation, which helped me in the past, in no particular order:

* log into other gmail account (with a long history) using Chrome without any addons, log out and then immediately try logging into the primary account (ideally google should ask you if you want to add another account)

* log in from the same location. I once spent two years abroad, and could not log in to one of my accounts. I regained access only after returning to my home country

* if you are working in an organization that owns an IP range, try logging in from work, i.e. do not use publicly available ISP.

You'll get best results if you can combine two or more of these points. Unfortunately even following this advice you are not guaranteed to be successful...

For the future reference, the only prevention that I know which works 100% times is using YubiKey for 2FA. 2FA with TOTP codes often helps unlocking the account, but I had cases where even the codes did not help.

Re: Ask HN: Gmail account security

#104
post #77
post #27

Earlier quoted context omitted.

> Needless to say, I will never again use gmail for critically important things. That's a hot take. If it was critically important, you'd have 2FA and a recovery phone number associated with it - which would have prevented you from getting stuck in a trust-fail situation to begin with. Use whatever service you want, but your takeaway from this situation is a bit absurd. Edit to add: I'm not saying Google's algorithm…

I have 2FA and a recovery email on my Gmail account, yet I have run into this issue. If Google thinks something is suspicious, it will decline your 2FA codes and recovery attempts—it will just tell you that you entered the wrong code. Only after you finally get back in do you find an email in your inbox explaining that the correct code was entered, but Google blocked it because it was suspicious. This happens to me f…

If you're entering a code, the 2FA method you're using is still susceptible to mitm-style phishing attacks, which is what this kind of location based check is securing against. You'd need a push notification or yubikey based 2fa check to get the same level of security.

Re: Ask HN: Gmail account security

#105
post #60
post #6

I stopped using gmail. I pay for my own domain (approx $10 per year and subscribe a hosting service that costs about $4/month). The total cost is not much different from a paid google email which is about $50/year. If I happened to forget/lose all passwords (lost laptop, burned house etc.), I would probably need to deal with the hosting company who would try to identify me with my credit card or some other way (phone…

In most cases it’s easy to social engineer hosting company staff into granting unauthorized access (even the major ones) all it takes is a bit of know-how and maybe a photoshopped ID. The weakest link in any security stack is always the human element. The fact that Google makes it impossible to get in touch with a human is why I trust it.

It can be done but it is not guaranteed. Smaller companies have more geeky staff who would be more suspicious and wouldn't let that easily to be had. They have more accountability.

I hear that many accounts of celebrities get hacked and I wonder how? Apparently even with 2FA it is not that secure. Some countries let you order a replacement SIM quite easily and then it can get intercepted (maybe by stealing from mailbox or similarly). This appears to be a reason why google has been refusing access even with 2FA in place.

Re: Ask HN: Gmail account security

#106

Earlier quoted context omitted.

Yes. It’s great!

Good to hear. I’ve been with them for a few years and support was one of the reasons I moved over from Gmail but I’ve never actually needed it.

I tried it, they are responsive and helpful.

A bug I reported is actually sent to the development team, and it's fixed. It took 5 weeks, though.

Re: Ask HN: Gmail account security

#107

One day I logged in to my Amazon account from a different country. Mind you, I have 2FA/OTP enabled in my account, and I entered it correctly. They also made me click on a link they sent via email to "verify my login". A couple hours later my account was blocked due to "suspicious login(s)" (i.e. mine), and the order I placed cancelled. They had me wait 24h until I could contact someone at support that could unblock…

The amount of trust that providers put in phone numbers is absolutely insane.

Re: Ask HN: Gmail account security

#108

Yep, and it was even more aggravating. > have three gmail accounts > primary, name.surname@gmail.com > secondary, name.surname.purchases@gmail.com > tertiary, name.surname.work@gmail.com > secondary and tertiary have primary as a recovery address > log in/out once a week in 2nd and 3rd > last August, try to log into name.surname.work > "Password is incorrect" > WTH?! of course it's correct. > try several times, Googl…

Set up a real email provider, forward your mail from google to them, and transition over.

If you want real identity security, reg your own domain, and move it with you.

Re: Ask HN: Gmail account security

#109
post #44
post #16

That doesn't help OP now, but I found it helpful to enable 2FA with Google Authenticator, and keep emergency backup codes in a safe place. It's slightly more hassle, but there are less 'soft AI' barriers between you and your successful login. I'd also suggest not to rely on a phone number as 2nd factor, it's not that super safe.

I'd suggest not to rely on google for anything you wouldn't want to lose.

2022 me agrees with you, but 2003 me getting an invite to GMail when it was a brand new service and essentially a completely different company with a different landscape didn't know better. Now I have nearly two decades of accounts and things tied to GMail =(
Post reply on HN