Live data from Hacker News

Ask HN: Gmail account security

news.ycombinator.com

231–240 of 807 posts

Re: Ask HN: Gmail account security

#231
I had an ancient Google account that I hadn't logged into in forever that put me into a similar recovery loop. I had the correct password for the account and it said I was logging in from a new device and asked for my recovery email. It sent a code to my recovery email account and I entered the code into the page.

So Google knew the following:

  1) I have the correct password to the Google account
  2) The recovery email address is valid and the code I entered matched
Despite that, after entering the code I received an error message stating essentially "Thank you for providing the correct code however we are still unable to verify your account". I then reached out to a contact within Google and they escalated the issue and the account access was restored for about a week or so before it went back into the same recovery loop. I gave up after that.

Re: Ask HN: Gmail account security

#232
I’ve also noticed that google like logging me out regularly if I’m using more filtering tools (think pihole etc). The ridiculous part is I’m on a static IP…google damn well knows it’s me

Re: Ask HN: Gmail account security

#233

Earlier quoted context omitted.

I am my own domain registrar.

And can any random person with a gmail or outlook or yahoo email address successfully email you and get replies back?

Having your own domain doesn't mean running the email server yourself. Or are you suggesting that they filter by registrar?

Re: Ask HN: Gmail account security

#234

Had this. It was telling me to try again 'later'. Ok, i did 'try later' every day for three weeks, and they didn't let me in. Using the very same IP address as I used to always access it, no less. Then, I gave up, moved all my services to another email account, and after 2 or 3 months tried logging in, and it suddenly allowed me to log in. Needless to say, I will never again use gmail for critically important things.

My solution is, buy your own domain. It's cheap and it will cost you only 20$ a year or something like that. I'm not saying run your own email service (I do, but I recognize that it's complex and not worth for most people), but use a public email service (like also GMail) with your own domain. That way at least if you no longer can access your account, or you get banned, or whatever, you don't loose your address (sin…

I usually do use emails only on my own domains, but in this specific instance I wanted an account that could not be easily traced to me (nothing illegal, just some investigative activity), and this was how I've found out how erratic and merciless our new Google AI overlords are.

Re: Ask HN: Gmail account security

#236

Earlier quoted context omitted.

I am my own domain registrar.

And can any random person with a gmail or outlook or yahoo email address successfully email you and get replies back?

In my experience, the moment someone emails your domain (at least on Gmail) your domain seems to become whitelisted almost instantaneously, even if others receive your email as spam. I don't know about Yahoo, but the problem is usually reaching out first. Generally, deliverability seems quite fine as long as you don't go for the cheapest package deal and implement all the modern protocols (SPF, DKIM, DMARC, etc.). Amazon IP addresses also seem to do quite well because Amazon has its own spam prevention system that's tied to your AWS account.

Having said that said, I haven't had a failed delivery in years and I host my email on a cheap VPS. I only started getting deliverability problems when I ignored my mail client's (and server's) warnings before sending a 100MiB email through a mail server that also hosted a TOR relay, which was pretty stupid in hindsight.

Mail deliverability isn't quite as bad as people seem to think it is, but if mail delivery to the big four fails, there's almost never a way to troubleshoot it. That's kind of a pain, I suppose.

Re: Ask HN: Gmail account security

#237
post #67

They also do this thing now where they block [1] smaller browsers (even ones using the latest version of chromium) under the guise of security. According to their docs they're fighting MITMs by generally disallowing any browser they can't identify (so the big few). If you're not on a whitelisted browser by Google, you can't log in (effectively, use) any of their properties. This feels very anti-competitive to me. Not…

Please dont post links to programs that arent even publicly available.

Re: Ask HN: Gmail account security

#238

Had this. It was telling me to try again 'later'. Ok, i did 'try later' every day for three weeks, and they didn't let me in. Using the very same IP address as I used to always access it, no less. Then, I gave up, moved all my services to another email account, and after 2 or 3 months tried logging in, and it suddenly allowed me to log in. Needless to say, I will never again use gmail for critically important things.

My solution is, buy your own domain. It's cheap and it will cost you only 20$ a year or something like that. I'm not saying run your own email service (I do, but I recognize that it's complex and not worth for most people), but use a public email service (like also GMail) with your own domain. That way at least if you no longer can access your account, or you get banned, or whatever, you don't loose your address (sin…

And if you don't run a local mail client like Thunderbird, make sure to take a Google Takeout backup as frequently as your threshold for losing recent mail. The backup of GMail includes all your mail in a standard .mbox format.

Re: Ask HN: Gmail account security

#239

One day I logged in to my Amazon account from a different country. Mind you, I have 2FA/OTP enabled in my account, and I entered it correctly. They also made me click on a link they sent via email to "verify my login". A couple hours later my account was blocked due to "suspicious login(s)" (i.e. mine), and the order I placed cancelled. They had me wait 24h until I could contact someone at support that could unblock…

It's absolutely bonkers what stupid crap some companies would call "security", and what lengths they'd go to enforce it.

- Security questions. Yeah, right, please give us what amounts to a password, but that other people likely know, and that we'll probably store in plaintext. You'll use this much weaker backup password if you forget your real one.

- A time component. Any kind of it. Sessions should not have an expiration time, period. Not unless I specifically checked a box that I want a session that expires. I never, ever want to be greeted with a login form when I follow some link when I've already logged into this thing a hundred times in this browser. This may have made sense 15 years ago when people shared computers, but people aren't sharing computers any more.

- Related: required password changes once a certain time period. Bonus points if I can't reuse any password I had in the past. You want me to forget my password? Because this is how you make me forget my password.

- Doing anything with IP addresses besides packet routing. Yes, my ISP uses a single IP address for at least several tens of subscribers. No, it's not my fault and I should not be punished for this. And no, if I went to other country, this doesn't mean I'm dangerous to the security my own accounts, ffs. You shouldn't care. You were provided with correct credentials, and you thus must log me in with no hindrance.

Re: Ask HN: Gmail account security

#240
post #53

Earlier quoted context omitted.

Can I ask which news? I'm already a happy Fastmail customer, just curious.

This [1] Neat fact, Google is yet to tell me they are making this change to my account. [1] https://arstechnica.com/gadgets/2022/01/google-tells-free-g-...

Same. Has anyone heard of anyone who HAS gotten a notification?
Post reply on HN