I have an account that I frequently sign into in an incognito session. Every time I do, Google emails the same account saying that it doesn't recognize the device. I've tried requesting that it remembers the device, but despite the browser and IP address staying the same, it doesn't seem to matter. Though it also appears that I can ignore these warnings entirely. The biggest issue that I have is that I have an email…
Perhaps you'd have more luck using a Firefox Container instead.
Ask HN: Gmail account security
171–180 of 807 posts
Re: Ask HN: Gmail account security
#172I stopped using gmail. I pay for my own domain (approx $10 per year and subscribe a hosting service that costs about $4/month). The total cost is not much different from a paid google email which is about $50/year. If I happened to forget/lose all passwords (lost laptop, burned house etc.), I would probably need to deal with the hosting company who would try to identify me with my credit card or some other way (phone…
In most cases it’s easy to social engineer hosting company staff into granting unauthorized access (even the major ones) all it takes is a bit of know-how and maybe a photoshopped ID. The weakest link in any security stack is always the human element. The fact that Google makes it impossible to get in touch with a human is why I trust it.
I still host my mail at home and am my own registrar. There are still human elements of course but I've minimized them to the extent that is currently feasible.
Re: Ask HN: Gmail account security
#173Yep, and it was even more aggravating. > have three gmail accounts > primary, name.surname@gmail.com > secondary, name.surname.purchases@gmail.com > tertiary, name.surname.work@gmail.com > secondary and tertiary have primary as a recovery address > log in/out once a week in 2nd and 3rd > last August, try to log into name.surname.work > "Password is incorrect" > WTH?! of course it's correct. > try several times, Googl…
Perhaps you're not supposed to have more than 1 gmail account, and the assumptions in their code cannot deal with more than 1 account per user, or worse, they actively try to discourage it.
Re: Ask HN: Gmail account security
#174Earlier quoted context omitted.
> Needless to say, I will never again use gmail for critically important things. That's a hot take. If it was critically important, you'd have 2FA and a recovery phone number associated with it - which would have prevented you from getting stuck in a trust-fail situation to begin with. Use whatever service you want, but your takeaway from this situation is a bit absurd. Edit to add: I'm not saying Google's algorithm…
I have 2FA and a recovery email on my Gmail account, yet I have run into this issue. If Google thinks something is suspicious, it will decline your 2FA codes and recovery attempts—it will just tell you that you entered the wrong code. Only after you finally get back in do you find an email in your inbox explaining that the correct code was entered, but Google blocked it because it was suspicious. This happens to me f…
That perhaps this deals with a very real threat? Google has no incentive to make it difficult for you to log in, it's the exact opposite.
Re: Ask HN: Gmail account security
#175One day I logged in to my Amazon account from a different country. Mind you, I have 2FA/OTP enabled in my account, and I entered it correctly. They also made me click on a link they sent via email to "verify my login". A couple hours later my account was blocked due to "suspicious login(s)" (i.e. mine), and the order I placed cancelled. They had me wait 24h until I could contact someone at support that could unblock…
The amount of trust that providers put in phone numbers is absolutely insane.
Re: Ask HN: Gmail account security
#176They also do this thing now where they block [1] smaller browsers (even ones using the latest version of chromium) under the guise of security. According to their docs they're fighting MITMs by generally disallowing any browser they can't identify (so the big few). If you're not on a whitelisted browser by Google, you can't log in (effectively, use) any of their properties. This feels very anti-competitive to me. Not…
Re: Ask HN: Gmail account security
#177Yep, and it was even more aggravating. > have three gmail accounts > primary, name.surname@gmail.com > secondary, name.surname.purchases@gmail.com > tertiary, name.surname.work@gmail.com > secondary and tertiary have primary as a recovery address > log in/out once a week in 2nd and 3rd > last August, try to log into name.surname.work > "Password is incorrect" > WTH?! of course it's correct. > try several times, Googl…
Set up a real email provider, forward your mail from google to them, and transition over. If you want real identity security, reg your own domain, and move it with you.
Of course, it just shifts your risk to the domain registrar, so don't use someone too cheap. It's worth paying a decent fee for decent service here.
Re: Ask HN: Gmail account security
#178Earlier quoted context omitted.
It's incentivized top-to-bottom. Every audit is structured around checking boxes, absolutely zero interest in actual security. Just state you have processes, that they meet the loosely written (or in some cases bizarrely specific) spec, and be able to provide some writing that explain them at least at a surface level. This is the case for just about every framework, and even though these systems are just for window d…
I recently quit my job in Information Security. We used the NIST 800-53 framework. 99% of people following security frameworks just blindly check in boxes during audits or control assessments. A security control/requirement can’t be met? No problem! Just create another piece of paperwork accepting the risk and get it signed off by the system owner (who has the most incentive to not inconvenience their project or depa…
As a result, unless you can satisfy every one of their requirements, regardless of mitigating controls, you cannot get installed. Even if you're a security product whose ultimate use case is discovering in-progress exploits.
I'm not sure if that's an example of the system working or being broken. But overall, Information Security is a complicated problem.
Re: Ask HN: Gmail account security
#179Yep, and it was even more aggravating. > have three gmail accounts > primary, name.surname@gmail.com > secondary, name.surname.purchases@gmail.com > tertiary, name.surname.work@gmail.com > secondary and tertiary have primary as a recovery address > log in/out once a week in 2nd and 3rd > last August, try to log into name.surname.work > "Password is incorrect" > WTH?! of course it's correct. > try several times, Googl…
Set up a real email provider, forward your mail from google to them, and transition over. If you want real identity security, reg your own domain, and move it with you.
I'm pretty confident that Gmail is more secure than the domain registrar if you're really attacked. At least do your research carefully on this one. Domains do get stolen.
As always, consider your own threat model. But if you're a civilian? Wow, just hope you can walk away from the lockout.
Re: Ask HN: Gmail account security
#180I'm having a hard time getting my head wrapped around the idea of relying on Gmail (or any other online identity provider) without enabling 2-factor authentication. The best way to avoid this kind of "AI hell" is just to take control of your own account security and set up some additional factors.