Nearly every interaction I have had with Google in the last two years makes me think the company has devolved into warring factions that cannot communicate let alone coordinate for the betterment of their users. Do they not eat their own cooking, or how do they manage to make everything so dysfunctional?
Ask HN: Gmail account security
181–190 of 807 posts
Re: Ask HN: Gmail account security
#182Re: Ask HN: Gmail account security
#183Re: Ask HN: Gmail account security
#184Earlier quoted context omitted.
Set up a real email provider, forward your mail from google to them, and transition over. If you want real identity security, reg your own domain, and move it with you.
> If you want real identity security, reg your own domain, and move it with you. I'm pretty confident that Gmail is more secure than the domain registrar if you're really attacked. At least do your research carefully on this one. Domains do get stolen. As always, consider your own threat model. But if you're a civilian? Wow, just hope you can walk away from the lockout.
Re: Ask HN: Gmail account security
#185One day I logged in to my Amazon account from a different country. Mind you, I have 2FA/OTP enabled in my account, and I entered it correctly. They also made me click on a link they sent via email to "verify my login". A couple hours later my account was blocked due to "suspicious login(s)" (i.e. mine), and the order I placed cancelled. They had me wait 24h until I could contact someone at support that could unblock…
It's incentivized top-to-bottom. Every audit is structured around checking boxes, absolutely zero interest in actual security. Just state you have processes, that they meet the loosely written (or in some cases bizarrely specific) spec, and be able to provide some writing that explain them at least at a surface level. This is the case for just about every framework, and even though these systems are just for window d…
https://www.go350.com/posts/they-want-us-to-be-compliant-not...
Re: Ask HN: Gmail account security
#186Currently, I use a posteo mail, which costs me 1€ (I believe) per month, for the important stuff. Mails which come as part of my webhosting package for most of the other stuff. And a free adress (web.de) as experiment, but it didn't turn out too bad so I keep it for unimportant stuff They just send ads as mail once a week. Calling this "mildly annoying" is exaggerated already.
Yea, so the takeaway (imo) is, leave the sinking ship before it sinks you. The process may take weeks or months if you proceed it relaxed (that's how I did it), so start before one of your important addresses gets hit.
Re: Ask HN: Gmail account security
#187They also do this thing now where they block [1] smaller browsers (even ones using the latest version of chromium) under the guise of security. According to their docs they're fighting MITMs by generally disallowing any browser they can't identify (so the big few). If you're not on a whitelisted browser by Google, you can't log in (effectively, use) any of their properties. This feels very anti-competitive to me. Not…
Wow, that's awful. I wonder who's idea it was? Is it doing anything more than checking user agent (trivial to spoof), because if not that seems entirely hostile.
Re: Ask HN: Gmail account security
#188Had this. It was telling me to try again 'later'. Ok, i did 'try later' every day for three weeks, and they didn't let me in. Using the very same IP address as I used to always access it, no less. Then, I gave up, moved all my services to another email account, and after 2 or 3 months tried logging in, and it suddenly allowed me to log in. Needless to say, I will never again use gmail for critically important things.
That way at least if you no longer can access your account, or you get banned, or whatever, you don't loose your address (since you can just move to another provider).
Also, use an email client on your PC (such as Thunderbird) and configure it to keep a copy of all your emails locally (and possibly have the PC backed up). That way if you loose access to your account you don't loose access to your mail, that you can even upload again in the new provider server.
Re: Ask HN: Gmail account security
#189They also do this thing now where they block [1] smaller browsers (even ones using the latest version of chromium) under the guise of security. According to their docs they're fighting MITMs by generally disallowing any browser they can't identify (so the big few). If you're not on a whitelisted browser by Google, you can't log in (effectively, use) any of their properties. This feels very anti-competitive to me. Not…
You could try creating an issue in the Cloud Identity issue tracker (Cloud Identity is Google's API for letting websites have a "Login with Google" thing): https://issuetracker.google.com/issues/new?component=522910&...
Re: Ask HN: Gmail account security
#190Earlier quoted context omitted.
It's incentivized top-to-bottom. Every audit is structured around checking boxes, absolutely zero interest in actual security. Just state you have processes, that they meet the loosely written (or in some cases bizarrely specific) spec, and be able to provide some writing that explain them at least at a surface level. This is the case for just about every framework, and even though these systems are just for window d…
I recently quit my job in Information Security. We used the NIST 800-53 framework. 99% of people following security frameworks just blindly check in boxes during audits or control assessments. A security control/requirement can’t be met? No problem! Just create another piece of paperwork accepting the risk and get it signed off by the system owner (who has the most incentive to not inconvenience their project or depa…