Live data from Hacker News

Ask HN: Gmail account security

news.ycombinator.com

211–220 of 807 posts

Re: Ask HN: Gmail account security

#211
They have calculated that overall, a non-negligible amount of users will be hacked unless they have their system the way it is. Sure some accounts will get locked out, but overall it's a net benefit. There are hidden variables.

Re: Ask HN: Gmail account security

#212
post #194

Earlier quoted context omitted.

That aspect is significantly worsened if your country has had proper electronic IDs for nearly two decades. I laugh my ass off but also shed a tear each and every time some foreign provider asks for "identification". Security questions, electrical bills and selfies, medieval garbage. But I guess I should be happy fax usage has dwindled somewhat.

Fax usage has not dwindled at all for hospital medical records; it's still the primary way of transferring records from one hospital to another if they don't have the same computer software running the hospital. It's ridiculous.

Is this a niche waiting to be exploited?

Re: Ask HN: Gmail account security

#213
post #194

Earlier quoted context omitted.

Fax usage has not dwindled at all for hospital medical records; it's still the primary way of transferring records from one hospital to another if they don't have the same computer software running the hospital. It's ridiculous.

Is this a niche waiting to be exploited?

Yes. The public good derived from sane EHR interoperability would be enormous. Lower costs, better treatments, more informed policies...

But there are lots of political barriers. NHS is trying, and pretty open to private tenders. I'm actually working on a very related field.

Smaller or more atomized healthcare systems than NHS would be probably even difficult to deal with initially.

Re: Ask HN: Gmail account security

#215
post #25

Yep, have had that issue for over a year now, I am completely unable to access my old gmail account despite having the password, recovery email and everything else. Just says "you can’t sign in" and that's it: https://i.imgur.com/4YrElkJ.png

Try using a VPN to log in from the location you last used the account

Re: Ask HN: Gmail account security

#216

Earlier quoted context omitted.

> If you want real identity security, reg your own domain, and move it with you. I'm pretty confident that Gmail is more secure than the domain registrar if you're really attacked. At least do your research carefully on this one. Domains do get stolen. As always, consider your own threat model. But if you're a civilian? Wow, just hope you can walk away from the lockout.

I am my own domain registrar.

And can any random person with a gmail or outlook or yahoo email address successfully email you and get replies back?

Re: Ask HN: Gmail account security

#217

Earlier quoted context omitted.

I’d recommend a non-Google 2FA app. Microsoft has one, and Authy is popular. Personally I’m happy with OTP Auth. Some password managers can also handle 2FA, e.g. Strongbox.

I'd recommend andOTP here as it is open source and not tied to any company that's trying to sell you anything.

Seconding andOTP[1] or Aegis,[2] if you're looking for an Android app that only handles OTP authentication. Both of these apps allow file-based import/export so that you can back up your codes and restore them elsewhere, no proprietary cloud service needed.

[1] https://github.com/andOTP/andOTP

[2] https://getaegis.app/

I'm not impressed with Authy's privacy policy, especially this part which mirrors the Google issues:[3]

> We use the information we gather from you to monitor for unusual or suspicious activity in your account, to communicate with you about your account, and as additional information that can be used to validate who you are if you need to recover your account or your account has been or may be compromised.

Authy also collects and shares more of your private information than most OTP apps:[3]

> When you use our app we collect: Your phone number, device information, and email address.

> We also share your information with our third party service providers as necessary for them to provide their services to us. We may also have to share your information with third parties if required to do so by law.

> Your information will be transferred to the U.S.

[3] https://www.twilio.com/legal/privacy/authy

Re: Ask HN: Gmail account security

#219
Your only option is a helpful googler who can fill out the internal "help recover an account" form. You this sucks. But having accounts stolen sucks too. I think Google is between a rock and a hard place here. But anyways, sucks.

-Xoogler

Re: Ask HN: Gmail account security

#220

Had this. It was telling me to try again 'later'. Ok, i did 'try later' every day for three weeks, and they didn't let me in. Using the very same IP address as I used to always access it, no less. Then, I gave up, moved all my services to another email account, and after 2 or 3 months tried logging in, and it suddenly allowed me to log in. Needless to say, I will never again use gmail for critically important things.

My solution is, buy your own domain. It's cheap and it will cost you only 20$ a year or something like that. I'm not saying run your own email service (I do, but I recognize that it's complex and not worth for most people), but use a public email service (like also GMail) with your own domain. That way at least if you no longer can access your account, or you get banned, or whatever, you don't loose your address (sin…

No post body was provided.
Post reply on HN