Live data from Hacker News

Ask HN: Gmail account security

news.ycombinator.com

321–330 of 807 posts

Re: Ask HN: Gmail account security

#321

Had this. It was telling me to try again 'later'. Ok, i did 'try later' every day for three weeks, and they didn't let me in. Using the very same IP address as I used to always access it, no less. Then, I gave up, moved all my services to another email account, and after 2 or 3 months tried logging in, and it suddenly allowed me to log in. Needless to say, I will never again use gmail for critically important things.

My solution is, buy your own domain. It's cheap and it will cost you only 20$ a year or something like that. I'm not saying run your own email service (I do, but I recognize that it's complex and not worth for most people), but use a public email service (like also GMail) with your own domain. That way at least if you no longer can access your account, or you get banned, or whatever, you don't loose your address (sin…

Or get a paid e-mail service where you can have support. I use Fastmail for this exact reason.

Re: Ask HN: Gmail account security

#322
post #311

Those of us who move around quite often can attest to how frustrating the security of online services has gotten. It can get even worse if you provide a phone number for "added security" and find yourself in a different country with a different phone. I've witnessed a few fellow travelers getting locked out of accounts because they couldn't access the SMS sent to their home phone number and the app was ignoring the c…

I know the pain of the internet with borders.

Paypal phone support literally told me to close my Dutch account and open a new German account so that I can use paypal in Germany. If you can login to paypal from abroad, that is a bug according to them, you're not supposed to be able to login from abroad (like when on holiday) and need to make a new account instead. (I currently start a VPN into NL every time I need to use paypal; one more reason to avoid them.)

In their defense: at least paypal has phone support. Try that with a gmail account.

Re: Ask HN: Gmail account security

#323
post #261

Earlier quoted context omitted.

You should be able to image her hard disk, and probably boot it up in a VM. Windows activation might complain in that case, but her data will be there.

> You should be able to image her hard disk, and probably boot it up in a VM. Is that still an option? I haven't used Windows for a long time, but I believe Microsoft has been pushing towards enabling BitLocker by default for everyone. If you don't have the BitLocker recovery key, or access to the user's Microsoft cloud account (which AFAIK has a copy of the BitLocker recovery key), the only way to decrypt the hard d…

If you have BitLocker enabled, you'll know about it. It's not the kind of thing that happens by accident.

Re: Ask HN: Gmail account security

#324
post #278

I had this in ~2014 at an event. It literally would not let me log in no matter what. This did reinforce that running my own email server was a good idea. Like, what are you going to do if it actually is important? Call google support? I'd be surprised if they have a helpdesk with humans nowadays, let alone to fix some free account at 1am in the morning. Or even if you get to talk to a human, what are they going to d…

>Google thought the IP address was in Russia and I guess that makes it suspicious? (Feels a bit odd that entire countries are basically banned.

I'm not sure why you immediately jumped to the conclusion that google is blocking entire countries. It seems fairly reasonable to block signins from russia if the account was created and has a history of signing in from another far-away country (eg. US).

>Not as if criminals can't use a VPS or VPN, it's security theater and seems insulting to everyone living there: they're all considered guilty until proven innocent.)

Google is probably doing more checks than looking at the country code from a geoip lookup. VPN/VPS IPs are easily distinguished from typical IPs (eg. residential internet and/or mobile internet).

Re: Ask HN: Gmail account security

#325
I understand how you end up here - after a decade or more of micro-optimizations down a pit of the newest/most advanced scam and take over techniques... but at some point you need to sit back, zoom out and look at collectively what you've created and see if you are catching a bit too much in the net.

I feel like Risk underwriting at Finance/FinTech companies goes through something similar... the list of rules only ever gets longer/gets added to.. I don't know that anyoen rewinds the clock every 5 years and starts from a clean slate to build out a new model.

Re: Ask HN: Gmail account security

#326
post #67

They also do this thing now where they block [1] smaller browsers (even ones using the latest version of chromium) under the guise of security. According to their docs they're fighting MITMs by generally disallowing any browser they can't identify (so the big few). If you're not on a whitelisted browser by Google, you can't log in (effectively, use) any of their properties. This feels very anti-competitive to me. Not…

A browser environment designed for researching is something I've been investigating lately. I want to stay with Chromium for convenience (Chrome for work, ungoogled-chromium for personal). Right now I see two paths that might work for me: - A standalone browser that I use only for research purposes. Currently evaluating Bonsai [1] and am interested in Synth. - A suite of tools that makes bookmarking and organizing ea…

Awesome. To keep focus on the main topic, feel free to email me to chat more (FWIW I've done the 50 extension patchwork thing and generally find the extension experience to fractured and suboptimal for me).

Re: Ask HN: Gmail account security

#327

Had this. It was telling me to try again 'later'. Ok, i did 'try later' every day for three weeks, and they didn't let me in. Using the very same IP address as I used to always access it, no less. Then, I gave up, moved all my services to another email account, and after 2 or 3 months tried logging in, and it suddenly allowed me to log in. Needless to say, I will never again use gmail for critically important things.

I make a habit of

1. Forwarding everything to my free tier google apps for business on my domain

2. Annually logging into my throwaways. it seems if i login to them once a year from home, they dont pull this.

3. do NOT attempt to login to my throwaways from a proxies connection (SSH/SOCKS on a VPS or something like that, which i frequently use at work)

Re: Ask HN: Gmail account security

#328
post #67

They also do this thing now where they block [1] smaller browsers (even ones using the latest version of chromium) under the guise of security. According to their docs they're fighting MITMs by generally disallowing any browser they can't identify (so the big few). If you're not on a whitelisted browser by Google, you can't log in (effectively, use) any of their properties. This feels very anti-competitive to me. Not…

A browser environment designed for researching is something I've been investigating lately. I want to stay with Chromium for convenience (Chrome for work, ungoogled-chromium for personal). Right now I see two paths that might work for me: - A standalone browser that I use only for research purposes. Currently evaluating Bonsai [1] and am interested in Synth. - A suite of tools that makes bookmarking and organizing ea…

You might also like promnesia

https://github.com/karlicoss/promnesia#readme

And if you're interested we have a small discord server "awesome knowledge management" come join us!

https://discord.gg/XPNeDSQE2j

Re: Ask HN: Gmail account security

#329
post #27

Earlier quoted context omitted.

> Needless to say, I will never again use gmail for critically important things. That's a hot take. If it was critically important, you'd have 2FA and a recovery phone number associated with it - which would have prevented you from getting stuck in a trust-fail situation to begin with. Use whatever service you want, but your takeaway from this situation is a bit absurd. Edit to add: I'm not saying Google's algorithm…

Actually, I specifically declined setting up a recovery phone number because I accessed it from the location where receiving codes would be impossible on my phones. I always accessed it from the same IP using my own VPN server, entered the correct password, and still Google decided that they are 'not sure that it is not really me, try again later'. No thanks.

What about downloaded back up codes ? Phone push approval? U2f key? Authenticator app? Can't imagine complaining about being shut out if you didn't have at least one or all of these set up. Google even nags you about setting these up.

Re: Ask HN: Gmail account security

#330
post #287

Earlier quoted context omitted.

My solution is, buy your own domain. It's cheap and it will cost you only 20$ a year or something like that. I'm not saying run your own email service (I do, but I recognize that it's complex and not worth for most people), but use a public email service (like also GMail) with your own domain. That way at least if you no longer can access your account, or you get banned, or whatever, you don't loose your address (sin…

I did this! Kind of. I bought a domain and was lucky enough to get in to a custom domain email (and more) service with a big company years ago when they had a free version. Unfortunately... it was Google (so kind of hiring the wolf to care for my sheep, as it turns out). And now they're cutting off all of us free tier folks. Which I can't fault them for, but still blame them for. Because I'm petty and entitled or wha…

whoa! thanks for the heads up :/
Post reply on HN