Live data from Hacker News

Ask HN: Gmail account security

news.ycombinator.com

301–310 of 807 posts

Re: Ask HN: Gmail account security

#301

One day I logged in to my Amazon account from a different country. Mind you, I have 2FA/OTP enabled in my account, and I entered it correctly. They also made me click on a link they sent via email to "verify my login". A couple hours later my account was blocked due to "suspicious login(s)" (i.e. mine), and the order I placed cancelled. They had me wait 24h until I could contact someone at support that could unblock…

It's absolutely bonkers what stupid crap some companies would call "security", and what lengths they'd go to enforce it. - Security questions. Yeah, right, please give us what amounts to a password, but that other people likely know, and that we'll probably store in plaintext. You'll use this much weaker backup password if you forget your real one. - A time component. Any kind of it. Sessions should not have an expir…

> - Security questions. Yeah, right, please give us what amounts to a password, but that other people likely know, and that we'll probably store in plaintext. You'll use this much weaker backup password if you forget your real one.

A good password manager, such as KeePass, will generate a passphrase. That is, words. Use that instead. Even if they ask "what is your mother's maiden name" just make up a passphrase.

> - A time component. Any kind of it. Sessions should not have an expiration time, period. Not unless I specifically checked a box that I want a session that expires. I never, ever want to be greeted with a login form when I follow some link when I've already logged into this thing a hundred times in this browser.

Yes, but;

> This may have made sense 15 years ago when people shared computers, but people aren't sharing computers any more.

This is false. I know many people who share computers. I treat all my computers as shared even though they are not; it's safer that way.

> - Related: required password changes once a certain time period. Bonus points if I can't reuse any password I had in the past. You want me to forget my password? Because this is how you make me forget my password.

I agree that password changes after a certain time period is stupid. However, a password manager solves the problem of forgetting your password.

> - Doing anything with IP addresses besides packet routing. Yes, my ISP uses a single IP address for at least several tens of subscribers. No, it's not my fault and I should not be punished for this. And no, if I went to other country, this doesn't mean I'm dangerous to the security my own accounts, ffs. You shouldn't care. You were provided with correct credentials, and you thus must log me in with no hindrance.

100% this

Re: Ask HN: Gmail account security

#302
post #260
post #230

It’s this kind of thing that has had me moving most everything off Google over the last 6 months. It’s just not safe for me to have 20 years of photos, emails and documents in the hands of a company that may cut me loose at any moment. After decades of slowly moving my life to “the cloud”, I bought a Synology nas, and now all my stuff lives in my own house (though backed up externally, of course).

Curious about the backup solution.

rsync.net, just because I have a pile of storage with them that I’ve had forever and not really made good use of. Synology natively supports S3, which includes Glacier, which I may use some day if I feel like a nearly free solution.

Re: Ask HN: Gmail account security

#303
post #99

there needs to be some kind of law or regulation around this right? email has become as, if not more important as regular mail, and the government should be protecting access to it. try sending it to your senator and local representative. I think the FTC would also be interested in this. if google won’t even give you support for the issue, that should really be addressed by the government imo.

if the U.S. government offered an email an email service, I'd use it.

Re: Ask HN: Gmail account security

#304
post #255

Earlier quoted context omitted.

A plug from a very satisfied customer: I pay $5/month for Fastmail. I've emailed support before and reached a human within hours. They helped me with my problem, because it was their job and I'm paying them to do it. Email is too important to rely on a free service which has a history of shutting people out, at any time, for any reason.

Still the problem with Fastmail is the same as with Google. Leaning on 3rd party service that you have no control of. There are so many things that could go wrong there, they can be hacked, go bankrupt, closed by authorities, insided. Everyone should have an appropriate personal disaster recovery plan that includes stuff like recovering from loss of service supplier.

Well, there's always a risk profile no matter what you do. But the risk profile with a company that's obsessed with AI and doesn't believe in having any customer support is much higher than one that you pay and has very good customer support.

Re: Ask HN: Gmail account security

#305
post #228

Earlier quoted context omitted.

If someone wants to stop using gmail, it's horribly inconvenient to move to another service. You need to update your email with all your other accounts, which for most people is pretty much unfeasible. You can't take your @gmail.com address, which means switching email providers is extremely difficult. There should really be some consumer protection laws around email.

Email forwarding makes migrating away from Gmail substantially easier: https://support.google.com/mail/answer/10957 With this, you don't have to update your email on all of your accounts at once. You can do it at your own pace. Consumer protection laws requiring data portability would still be welcome.

That is nice, didn't realize you could do that. But yeah, people in the same spot as OP can't exactly do that if they're locked out for no apparent reason.

Re: Ask HN: Gmail account security

#306

Had this. It was telling me to try again 'later'. Ok, i did 'try later' every day for three weeks, and they didn't let me in. Using the very same IP address as I used to always access it, no less. Then, I gave up, moved all my services to another email account, and after 2 or 3 months tried logging in, and it suddenly allowed me to log in. Needless to say, I will never again use gmail for critically important things.

This is exactly my experience too. My Google accounts just randomly decide to stop working from time to time, and if I no longer have the same phone number that I did before (or if I'm traveling overseas and cannot get a "confirmation call"), there is no way at all to get in. Usually after a mysterious and unexplained period of time, my account gets un-flagged again and I can log in as per normal. The first time this…

I just ran into this yesterday. Tried to log into Paypal and forgot my pwd. I tried to reset it using the "Forgot password?" link. I entered my email address, and the response was "Sorry, we couldn’t confirm it’s you".

They won't let me reset my password.

Re: Ask HN: Gmail account security

#307

Had this. It was telling me to try again 'later'. Ok, i did 'try later' every day for three weeks, and they didn't let me in. Using the very same IP address as I used to always access it, no less. Then, I gave up, moved all my services to another email account, and after 2 or 3 months tried logging in, and it suddenly allowed me to log in. Needless to say, I will never again use gmail for critically important things.

This is exactly my experience too. My Google accounts just randomly decide to stop working from time to time, and if I no longer have the same phone number that I did before (or if I'm traveling overseas and cannot get a "confirmation call"), there is no way at all to get in. Usually after a mysterious and unexplained period of time, my account gets un-flagged again and I can log in as per normal. The first time this…

I just ran into this yesterday. Tried to log into Paypal and forgot my pwd. I tried to reset it using the "Forgot password?" link. I entered my email address, and the response was "Sorry, we couldn’t confirm it’s you".

They won't let me reset my password.

Re: Ask HN: Gmail account security

#308
post #67

They also do this thing now where they block [1] smaller browsers (even ones using the latest version of chromium) under the guise of security. According to their docs they're fighting MITMs by generally disallowing any browser they can't identify (so the big few). If you're not on a whitelisted browser by Google, you can't log in (effectively, use) any of their properties. This feels very anti-competitive to me. Not…

Hey, cool website !, The mailto: hyperlink on your careers button in the footer, has a typo, namely,

"mailto:careers@synth.app&subject=Synth Careers&body=Please attach resume!"

It should be,

"mailto:careers@synth.app?subject=Synth Careers&body=Please attach resume!"

that &subject instead of ?subject is causing that mailto link to not be imported properly by most mail apps, trivial thing, but thought I'd mention it.

Good luck with your app !

Re: Ask HN: Gmail account security

#309
post #67

They also do this thing now where they block [1] smaller browsers (even ones using the latest version of chromium) under the guise of security. According to their docs they're fighting MITMs by generally disallowing any browser they can't identify (so the big few). If you're not on a whitelisted browser by Google, you can't log in (effectively, use) any of their properties. This feels very anti-competitive to me. Not…

Its craziness all the way down. I have a google voice number which is my "default" number with my gmail accounts. All my gmail accounts were automatically migrated to use 2FA with this number which means if I lose all my google devices and I try to log into voice, I'll get 2FA I can't see because of the catch-22 situation of not being able to log into voice.

The only reason I caught this is because they send me a notice about 2FA and I thought, wait what 2FA am I using? Instead of them running a tiny check to see "Wait, is this person using a voice number" they did it anyway. Worse, they know this because if you go into the 2FA page manually it says in bold letters to not use a good voice number.

At this point I'm spooked and I'm just going to port my number into our account at work and have my work phone use this number instead of having a dual number phone with voice. Voice SMS is a mess too. 50% of services can't SMS it a code because Google blocks it. Other services won't accept it for SMS codes because its "not a real phone."

If I didn't catch this then there would have been a day where I'm locked out of my accounts with no apparent way back in.

Re: Ask HN: Gmail account security

#310

Earlier quoted context omitted.

It's absolutely bonkers what stupid crap some companies would call "security", and what lengths they'd go to enforce it. - Security questions. Yeah, right, please give us what amounts to a password, but that other people likely know, and that we'll probably store in plaintext. You'll use this much weaker backup password if you forget your real one. - A time component. Any kind of it. Sessions should not have an expir…

> - Security questions. Yeah, right, please give us what amounts to a password, but that other people likely know, and that we'll probably store in plaintext. You'll use this much weaker backup password if you forget your real one. A good password manager, such as KeePass, will generate a passphrase . That is, words. Use that instead. Even if they ask "what is your mother's maiden name" just make up a passphrase. > -…

> A good password manager

> a password manager solves the problem

Sorry but as a software developer myself, I can't trust a piece of software to store all my passwords and thus be a single point of failure for my entire digital life.

> This is false. I know many people who share computers.

With a single OS user account? Even android tablets these days come with multi-user support.

> I treat all my computers as shared even though they are not; it's safer that way.

Do you not have a password, and preferably full-disk encryption, on them?

Post reply on HN