Live data from Hacker News

Ask HN: Gmail account security

news.ycombinator.com

141–150 of 807 posts

Re: Ask HN: Gmail account security

#141
post #16

That doesn't help OP now, but I found it helpful to enable 2FA with Google Authenticator, and keep emergency backup codes in a safe place. It's slightly more hassle, but there are less 'soft AI' barriers between you and your successful login. I'd also suggest not to rely on a phone number as 2nd factor, it's not that super safe.

> enable 2FA with Google Authenticator [...] also suggest not to rely on a phone number as 2nd factor

Well, I have my PayPal account set up with a strong unique password and 2FA via an authenticator app. Recently installed the PayPal app on my smartphone, and it asked for CAPTCHA, password, 2FA token, and then additionally SMS to an old phone number I still had on file. How does it make sense to ask for 3 factors? At any rate, I logged in on the computer and updated the phone number. Still wouldn't let me log in on the smartphone, needed to contact customer support.

Look, I understand that many people choose bad passwords and they get pawned and all, and I'm glad that the providers are a bit smarter and use other factors (cookies, IP, phone number...), but it really penalises security and privacy conscious users. If you use strong passwords and 2FA, but use VPNs, switch phone numbers, clear cookies, etc., you get flagged and locked out. Very annoying.

Re: Ask HN: Gmail account security

#142
post #103

Things I can recommend in your situation, which helped me in the past, in no particular order: * log into other gmail account (with a long history) using Chrome without any addons, log out and then immediately try logging into the primary account (ideally google should ask you if you want to add another account) * log in from the same location. I once spent two years abroad, and could not log in to one of my accounts…

> using YubiKey for 2FA

Today Google/Gmail suddenly logged me out and asked me for the hardware key, and I thought no problem as I have OTP with my Password Manager, but OTP didn't work. I had the key somewhere else. Luckily after insisting a bit Google gave me the option to use my mobile Gmail app to verify it's me (note it was not Google Authenticator, why did they made me install it?). All this hassle even though I've been on the same ISP/IP range and computer for weeks. No VPN or anything.

On top of the multiple authentication options, I'm going to add a second hardware key in case I lose my main one and Google decides it's the only way to log in.

Edit: the OTP option is not there anymore in my Google account 2-Step Verification, but it did ask for it and it failed.

Re: Ask HN: Gmail account security

#143
post #7

Wasn't aware of this, but can't say I'm surprised. Personally, I'm still happy with Fastmail, which uses customer subscriptions fees to fund a professional support department, as well as contributing to email-related FOSS. (Among other things, obviously.)

I moved my email to Fastmail this week in the wake of the Google Apps announcement. Having your own domain is great since your email becomes provider-agnostic. While Fastmail had a great import tool, I could have transferred my Gmail myself from backups. I'll be ready to do the same if Fastmail goes under or is no longer competitive.

Re: Ask HN: Gmail account security

#144
post #99

there needs to be some kind of law or regulation around this right? email has become as, if not more important as regular mail, and the government should be protecting access to it. try sending it to your senator and local representative. I think the FTC would also be interested in this. if google won’t even give you support for the issue, that should really be addressed by the government imo.

There is not need for a law. Just don't use google.

Re: Ask HN: Gmail account security

#145

One day I logged in to my Amazon account from a different country. Mind you, I have 2FA/OTP enabled in my account, and I entered it correctly. They also made me click on a link they sent via email to "verify my login". A couple hours later my account was blocked due to "suspicious login(s)" (i.e. mine), and the order I placed cancelled. They had me wait 24h until I could contact someone at support that could unblock…

It's incentivized top-to-bottom. Every audit is structured around checking boxes, absolutely zero interest in actual security. Just state you have processes, that they meet the loosely written (or in some cases bizarrely specific) spec, and be able to provide some writing that explain them at least at a surface level. This is the case for just about every framework, and even though these systems are just for window d…

I recently quit my job in Information Security. We used the NIST 800-53 framework. 99% of people following security frameworks just blindly check in boxes during audits or control assessments. A security control/requirement can’t be met? No problem! Just create another piece of paperwork accepting the risk and get it signed off by the system owner (who has the most incentive to not inconvenience their project or department due to an outstanding security requirement).

The things I saw that were labeled as “acceptable risk” would drive me crazy. Maybe the government hires incompetent security practitioners? Do all organizations have this type of behavior behind the scenes?

Re: Ask HN: Gmail account security

#146
I have an account that I frequently sign into in an incognito session. Every time I do, Google emails the same account saying that it doesn't recognize the device. I've tried requesting that it remembers the device, but despite the browser and IP address staying the same, it doesn't seem to matter. Though it also appears that I can ignore these warnings entirely.

The biggest issue that I have is that I have an email account through my web hosting provider that isn't connected to Google. If I email anyone with a Gmail address, it gets rejected for being potential spam, despite not having any links or anything. Even if I respond to someone writing from a Gmail address, Google will reject it, saying that it was unsolicited since I was the one initiating the conversation, which is simply ridiculous. I usually end up logging into a separate Gmail account just to communicate with those users.

Re: Ask HN: Gmail account security

#147

Earlier quoted context omitted.

I’d recommend a non-Google 2FA app. Microsoft has one, and Authy is popular. Personally I’m happy with OTP Auth. Some password managers can also handle 2FA, e.g. Strongbox.

Any particular reason?

Aside from the other reasons cited, at least once in the past Google replaced Authenticator with a new app and I had to re-configure all of my 2FA from scratch to transfer over. Deeply untrustworthy, it's already bad enough having to reconfigure 2FA when I get a new phone without them forcing me to do it again.

I use Authy these days.

https://android.stackexchange.com/questions/20899/why-does-t...

Re: Ask HN: Gmail account security

#148
post #27

Earlier quoted context omitted.

> Needless to say, I will never again use gmail for critically important things. That's a hot take. If it was critically important, you'd have 2FA and a recovery phone number associated with it - which would have prevented you from getting stuck in a trust-fail situation to begin with. Use whatever service you want, but your takeaway from this situation is a bit absurd. Edit to add: I'm not saying Google's algorithm…

With Google’s nonexistent customer service I’d be afraid of being locked out for any arbitrary reason and having no recourse no matter what recovery procedures I prepared for. Contrast that to my bank where I can go to the branch, show ID, and get problems logging in resolved.

"With Google’s nonexistent customer service..."

What's needed is enough of these cases to bring a class action against Google.

It's over a decade since I've used a Google account and I was similarly ignored even back then.

Re: Ask HN: Gmail account security

#149

This is because most people use Gmail for basically all their online accounts: if you don't directly login to the site via Gmail, you can use your account to change your password. Imagine the damage which can be done if a malicious user breaks into someone's Gmail, if not your own, then the average person who uses the same password everywhere and trusts Gmail with everything. Not defending the practice at all. It sho…

this only works if your post gets upvoted. which in the grand scheme of things is rare. have you been to the "new" page lately?

(you're all checking out the 'new' page now, aren't you?)

Re: Ask HN: Gmail account security

#150

I have an account that I frequently sign into in an incognito session. Every time I do, Google emails the same account saying that it doesn't recognize the device. I've tried requesting that it remembers the device, but despite the browser and IP address staying the same, it doesn't seem to matter. Though it also appears that I can ignore these warnings entirely. The biggest issue that I have is that I have an email…

Perhaps you'd have more luck using a Firefox Container instead.
Post reply on HN