Live data from Hacker News

Ask HN: Gmail account security

news.ycombinator.com

111–120 of 807 posts

Re: Ask HN: Gmail account security

#111

One day I logged in to my Amazon account from a different country. Mind you, I have 2FA/OTP enabled in my account, and I entered it correctly. They also made me click on a link they sent via email to "verify my login". A couple hours later my account was blocked due to "suspicious login(s)" (i.e. mine), and the order I placed cancelled. They had me wait 24h until I could contact someone at support that could unblock…

The amount of trust that providers put in phone numbers is absolutely insane.

Or maybe do they really want your phone number? (Uninformed guess but isn't it valuable data?)

Re: Ask HN: Gmail account security

#112
post #27

Earlier quoted context omitted.

> Needless to say, I will never again use gmail for critically important things. That's a hot take. If it was critically important, you'd have 2FA and a recovery phone number associated with it - which would have prevented you from getting stuck in a trust-fail situation to begin with. Use whatever service you want, but your takeaway from this situation is a bit absurd. Edit to add: I'm not saying Google's algorithm…

With Google’s nonexistent customer service I’d be afraid of being locked out for any arbitrary reason and having no recourse no matter what recovery procedures I prepared for. Contrast that to my bank where I can go to the branch, show ID, and get problems logging in resolved.

A plug from a very satisfied customer: I pay $5/month for Fastmail. I've emailed support before and reached a human within hours. They helped me with my problem, because it was their job and I'm paying them to do it.

Email is too important to rely on a free service which has a history of shutting people out, at any time, for any reason.

Re: Ask HN: Gmail account security

#113

One day I logged in to my Amazon account from a different country. Mind you, I have 2FA/OTP enabled in my account, and I entered it correctly. They also made me click on a link they sent via email to "verify my login". A couple hours later my account was blocked due to "suspicious login(s)" (i.e. mine), and the order I placed cancelled. They had me wait 24h until I could contact someone at support that could unblock…

It's incentivized top-to-bottom. Every audit is structured around checking boxes, absolutely zero interest in actual security. Just state you have processes, that they meet the loosely written (or in some cases bizarrely specific) spec, and be able to provide some writing that explain them at least at a surface level.

This is the case for just about every framework, and even though these systems are just for window dressing, the auditors are mostly incompetent. A review a few years ago showed that 20-50% (depending on which of the Big 4 you've decided to hire) of audits were done incorrectly.

Re: Ask HN: Gmail account security

#114
I lost a google account that I had a recovery number set on.

Google used it, verified it, then said it wasn't enough, and there went an email account I had used for years.

No way to recover.

Re: Ask HN: Gmail account security

#115

One day I logged in to my Amazon account from a different country. Mind you, I have 2FA/OTP enabled in my account, and I entered it correctly. They also made me click on a link they sent via email to "verify my login". A couple hours later my account was blocked due to "suspicious login(s)" (i.e. mine), and the order I placed cancelled. They had me wait 24h until I could contact someone at support that could unblock…

The amount of trust that providers put in phone numbers is absolutely insane.

[deleted]

Re: Ask HN: Gmail account security

#116
post #96

Earlier quoted context omitted.

> 2FA with Google Authenticator I just wanted to recommend Aegis as an alternative to Google Authenticator. It allows backing up codes to an encrypted (password protected) file. Plus it's FOSS.

I use 1password as an Authenticator replacement, which saves time when logging in.

I hope you're not storing your passwords in there too

Re: Ask HN: Gmail account security

#117
post #67

They also do this thing now where they block [1] smaller browsers (even ones using the latest version of chromium) under the guise of security. According to their docs they're fighting MITMs by generally disallowing any browser they can't identify (so the big few). If you're not on a whitelisted browser by Google, you can't log in (effectively, use) any of their properties. This feels very anti-competitive to me. Not…

Just signed up. Your idea appeals to me. Hope I can take it for a spin soon!

Re: Ask HN: Gmail account security

#119
I had the same issue. I just gave up and came a while later with the same IP and eventually got through. It’s ridiculous that they both allow you to not setup 2FA and don’t let you in without whatever they deem required.

I eventually started using 1Password for all my backup google accounts to setup TOTP making it just as convenient as without 2FA. It was still a pain to have to wait and go through the process though.

Post reply on HN