Live data from Hacker News

Ask HN: Gmail account security

news.ycombinator.com

261–270 of 807 posts

Re: Ask HN: Gmail account security

#261

My 87 year old grandma's computer wouldn't boot. We set her up on a new laptop. But we couldn't remember her Gmail password. We never recovered her account, including any photos backed up to Google Photos.

You should be able to image her hard disk, and probably boot it up in a VM. Windows activation might complain in that case, but her data will be there.

> You should be able to image her hard disk, and probably boot it up in a VM.

Is that still an option? I haven't used Windows for a long time, but I believe Microsoft has been pushing towards enabling BitLocker by default for everyone. If you don't have the BitLocker recovery key, or access to the user's Microsoft cloud account (which AFAIK has a copy of the BitLocker recovery key), the only way to decrypt the hard disk is to boot the system the normal way (with SecureBoot enabled even), since the key is held on the TPM.

Re: Ask HN: Gmail account security

#262

Earlier quoted context omitted.

2022 me agrees with you, but 2003 me getting an invite to GMail when it was a brand new service and essentially a completely different company with a different landscape didn't know better. Now I have nearly two decades of accounts and things tied to GMail =(

Google Takeout is a pretty nice service still. It's good to back up your accounts regularly.

Unfortunately Takeout doesn't really do anything to help with purchases.

Re: Ask HN: Gmail account security

#263
post #197
post #77

Earlier quoted context omitted.

I have 2FA and a recovery email on my Gmail account, yet I have run into this issue. If Google thinks something is suspicious, it will decline your 2FA codes and recovery attempts—it will just tell you that you entered the wrong code. Only after you finally get back in do you find an email in your inbox explaining that the correct code was entered, but Google blocked it because it was suspicious. This happens to me f…

I think we need to quit calling it AI, and instead call it AS: Actual Stupidity

Agreed. The moment we allow AI to take the blame for irresponsible decisions made by the humans who designed and maintain said AI, is the moment we stop holding people accountable for real damage done.

Account lockouts are bad enough, but more serious things driven by AI are bound to reveal their fallibility. I sincerely hope tech workers have the integrity to take responsibility, judging by the current political climate and its participants' willingness to venture into thinking (surrounding the value of human life, among other things) that was considered taboo not long ago.

The moral and practical capacities of AI will reflect the limits of those designing them, at best.

Re: Ask HN: Gmail account security

#264

I think we, "people", pushed companies to do this. There are billions of people creating various accounts. Hundreds of thousands of them had a weak password, or told their password to someone, etc, and their data leaked. There were so many news about "data leaks" and "security issues" in the past 20 years, and each time, a company was blamed, never a user. We even made laws, where letting people log in with only a pa…

I actually don't mind this take - it's no doubt the security rules for google services are a bit over the top, but it's not like they don't have good reason to do it; or even to be anti-user.

Re: Ask HN: Gmail account security

#265
post #16

That doesn't help OP now, but I found it helpful to enable 2FA with Google Authenticator, and keep emergency backup codes in a safe place. It's slightly more hassle, but there are less 'soft AI' barriers between you and your successful login. I'd also suggest not to rely on a phone number as 2nd factor, it's not that super safe.

I’d recommend a non-Google 2FA app. Microsoft has one, and Authy is popular. Personally I’m happy with OTP Auth. Some password managers can also handle 2FA, e.g. Strongbox.

1Password has had really nice 2FA support for years now

Re: Ask HN: Gmail account security

#266

Earlier quoted context omitted.

My solution is, buy your own domain. It's cheap and it will cost you only 20$ a year or something like that. I'm not saying run your own email service (I do, but I recognize that it's complex and not worth for most people), but use a public email service (like also GMail) with your own domain. That way at least if you no longer can access your account, or you get banned, or whatever, you don't loose your address (sin…

Quoted post unavailable.

I don't know if it's FUD, but it's true. It happened to a person I know, and in her case, the resolution was "ask around until a friend of a friend of a friend of a friend works at Google".

She literally had to ask her friend, who asked me, I asked one of my friends to ask one of his friends who works at Google to put in an internal ticket. It was thankfully resolved quickly (she lost access to all her work materials), but the process is insane.

Use your own domain with Fastmail. Yesterday.

Re: Ask HN: Gmail account security

#267
post #255

Earlier quoted context omitted.

A plug from a very satisfied customer: I pay $5/month for Fastmail. I've emailed support before and reached a human within hours. They helped me with my problem, because it was their job and I'm paying them to do it. Email is too important to rely on a free service which has a history of shutting people out, at any time, for any reason.

Still the problem with Fastmail is the same as with Google. Leaning on 3rd party service that you have no control of. There are so many things that could go wrong there, they can be hacked, go bankrupt, closed by authorities, insided. Everyone should have an appropriate personal disaster recovery plan that includes stuff like recovering from loss of service supplier.

This is a false equivalence.

Life on a crowded planet depends on third parties; choosing vendors well is a critical life skill.

Fastmail have a long-standing reputation for treating customers right; certainly not a reputation google shares.

Re: Ask HN: Gmail account security

#268

Had this. It was telling me to try again 'later'. Ok, i did 'try later' every day for three weeks, and they didn't let me in. Using the very same IP address as I used to always access it, no less. Then, I gave up, moved all my services to another email account, and after 2 or 3 months tried logging in, and it suddenly allowed me to log in. Needless to say, I will never again use gmail for critically important things.

Yeah this sounds like utter bullshit to me. What if you're travelling, all your devices get stolen, and you're logging in from a public computer or friend's computer to contact your family?

This is mindblowingly idiotic. Do they have such a bad vacation policy for their employees that not a single ONE of their engineering managers has experienced the above? Do they just sit in front of their desks for 365 days a year and never leave their country borders?

Re: Ask HN: Gmail account security

#269
I signed into an old Gmail account of mine that had a bitcoin private key backup. After signing in successfully, I searched for "bitcoin private key" in Gmail.

Within a second and before the search completed, I was immediately kicked out of all active sessions, and my account was locked.

Re: Ask HN: Gmail account security

#270
I had a different problem. On my wife's account she started receiving someone else's emails. Initially we suspected that her email was wrongly(typo) used in registration at various sites. But increasingly we noticed that the conversations in the mails were ongoing, implying continued usage of her address. We suspected her email was hacked and changed password, that didnt help. Eventually she had to abandon that email. The problem with free mail service is that the support you get is what you pay for.
Post reply on HN