Live data from Hacker News

Ask HN: Gmail account security

news.ycombinator.com

161–170 of 807 posts

Re: Ask HN: Gmail account security

#161

Earlier quoted context omitted.

With Google’s nonexistent customer service I’d be afraid of being locked out for any arbitrary reason and having no recourse no matter what recovery procedures I prepared for. Contrast that to my bank where I can go to the branch, show ID, and get problems logging in resolved.

A plug from a very satisfied customer: I pay $5/month for Fastmail. I've emailed support before and reached a human within hours. They helped me with my problem, because it was their job and I'm paying them to do it. Email is too important to rely on a free service which has a history of shutting people out, at any time, for any reason.

Ditto.

I'm a satisfied Fastmail paying user for years

Re: Ask HN: Gmail account security

#162
post #73
post #7

Wasn't aware of this, but can't say I'm surprised. Personally, I'm still happy with Fastmail, which uses customer subscriptions fees to fund a professional support department, as well as contributing to email-related FOSS. (Among other things, obviously.)

Fastmail looks great, but having "Get the email features you need, without giving up your privacy" and "Your data is always private" at the top of their homepage while knowing full well that is far from the case[0,1] seems disingenuous. [0] FastMail loses customers, faces calls to move over anti-encryption laws https://www.itnews.com.au/news/fastmail-loses-customers-face... [1] Goodbye FastMail https://www.ctrl.blog/…

Fastmail is not a zero-knowledge service. Unless I'm missing something, anti-encryption laws seem to be irrelevant, since they don't really change the position at all.

I suppose hypothetically if Fastmail was a zero-knowledge service that law might mean they need to break it, but it's not a zero-knowledge service so the issue doesn't arise.

You're going to be hard pressed to find a service provider which ignores valid warrants. Such a service provider would need to either operate unlawfully, or not hold the information (ie be zero-knowledge).

Even Protonmail, the bastion of email privacy, has supplied the IP address of a user in the face of a warrant.[0]

[0] https://techcrunch.com/2021/09/06/protonmail-logged-ip-addre...

Re: Ask HN: Gmail account security

#163
have old gmail account

no longer have associated phone number

Do have backup email (primary email).

Do have password.

Google doesn't care. Won't let me log in, won't send an email to the primary account for recovery, etc.

I've written it off. Essentially if I'm not paying someone for it, they don't care.

Re: Ask HN: Gmail account security

#164

Earlier quoted context omitted.

With Google’s nonexistent customer service I’d be afraid of being locked out for any arbitrary reason and having no recourse no matter what recovery procedures I prepared for. Contrast that to my bank where I can go to the branch, show ID, and get problems logging in resolved.

FYI, google has customer service if you're paying them. I pay $6 a month for gsuite. I've contacted customer service 3 times. Got them instantly.

They're supposed to have paid customer service for non-business users too if you pay for Google One, no idea how effective that is.

Re: Ask HN: Gmail account security

#165

Password reset functions for most providers often make 2FA hardware/software tokens useless. They fall back to email/sms to reset forgotten password/tokens. I guess it’s usability for majority over security that would lock out users.

If TOTP or Webauth is offered at all, usually it's some garbage like SMS. Twitch, eBay and Amazon all three are really disgustingly pushy with it with some bullshit excuses.

Re: Ask HN: Gmail account security

#166

Yep, and it was even more aggravating. > have three gmail accounts > primary, name.surname@gmail.com > secondary, name.surname.purchases@gmail.com > tertiary, name.surname.work@gmail.com > secondary and tertiary have primary as a recovery address > log in/out once a week in 2nd and 3rd > last August, try to log into name.surname.work > "Password is incorrect" > WTH?! of course it's correct. > try several times, Googl…

Perhaps you're not supposed to have more than 1 gmail account, and the assumptions in their code cannot deal with more than 1 account per user, or worse, they actively try to discourage it.

Shared accounts are a nightmare too. Google makes it a pain for a team of developers to share a single "test" account completely seperate from their individual accounts.

Re: Ask HN: Gmail account security

#167
post #161

Earlier quoted context omitted.

A plug from a very satisfied customer: I pay $5/month for Fastmail. I've emailed support before and reached a human within hours. They helped me with my problem, because it was their job and I'm paying them to do it. Email is too important to rely on a free service which has a history of shutting people out, at any time, for any reason.

Ditto. I'm a satisfied Fastmail paying user for years

Me 2

Re: Ask HN: Gmail account security

#168
post #73
post #7

Wasn't aware of this, but can't say I'm surprised. Personally, I'm still happy with Fastmail, which uses customer subscriptions fees to fund a professional support department, as well as contributing to email-related FOSS. (Among other things, obviously.)

Fastmail looks great, but having "Get the email features you need, without giving up your privacy" and "Your data is always private" at the top of their homepage while knowing full well that is far from the case[0,1] seems disingenuous. [0] FastMail loses customers, faces calls to move over anti-encryption laws https://www.itnews.com.au/news/fastmail-loses-customers-face... [1] Goodbye FastMail https://www.ctrl.blog/…

You are never safe from these shenanigans, not in Switzerland and not in Germany.

If you absolutely must have email out of the hands of low to mid grade government entities you need to implement the technical solutions yourself. If you want more, just forget it, if they want your mail they'll just get it at your endpoint anyway.

(also, "most email is unencrypted in transit" is a very out of date take, I've checked all correspondence I've had with medical practicioners in the past 2 years, and all where at least TLS 1.2 on the transport, close to half 1.3 - and i was sent around quite a lot last year)

Re: Ask HN: Gmail account security

#169
post #142
post #103

Things I can recommend in your situation, which helped me in the past, in no particular order: * log into other gmail account (with a long history) using Chrome without any addons, log out and then immediately try logging into the primary account (ideally google should ask you if you want to add another account) * log in from the same location. I once spent two years abroad, and could not log in to one of my accounts…

> using YubiKey for 2FA Today Google/Gmail suddenly logged me out and asked me for the hardware key, and I thought no problem as I have OTP with my Password Manager, but OTP didn't work . I had the key somewhere else. Luckily after insisting a bit Google gave me the option to use my mobile Gmail app to verify it's me (note it was not Google Authenticator, why did they made me install it?). All this hassle even though…

I once had a situation where I didn't have access to my YubiKey but I had backup codes (not from the authenticator app but the 10 codes you are given when you set up 2FA for the first time). I could log in but I thought I'll remove the YubiKey from the account and set up TOTP (Authenticator) instead. It turns out you cannot do this using only backup codes, you have to have the key! So if you loose your key and run out of your 10 codes, you may loose the access to the account forever! It seems that the only way to prevent this is to have two YubiKeys added to the account...
Post reply on HN