Live data from Hacker News

Ask HN: Gmail account security

news.ycombinator.com

361–370 of 807 posts

Re: Ask HN: Gmail account security

#361
I regularly get security notifications for an account I’ve since lost the password to, the notifications go to my primary email, and this means a malicious actor has my password. I can’t login via account recovery, using my backup email, for the same reasons as described so I’m at a stalemate with some random malicious hacker and have no way of solving the issue, and no idea what’s actually in the account. Fuck you google.

Re: Ask HN: Gmail account security

#362
post #268

Had this. It was telling me to try again 'later'. Ok, i did 'try later' every day for three weeks, and they didn't let me in. Using the very same IP address as I used to always access it, no less. Then, I gave up, moved all my services to another email account, and after 2 or 3 months tried logging in, and it suddenly allowed me to log in. Needless to say, I will never again use gmail for critically important things.

Yeah this sounds like utter bullshit to me. What if you're travelling, all your devices get stolen, and you're logging in from a public computer or friend's computer to contact your family? This is mindblowingly idiotic. Do they have such a bad vacation policy for their employees that not a single ONE of their engineering managers has experienced the above? Do they just sit in front of their desks for 365 days a year…

My guess is they get defrauded more often.

The scenario you present is a really obvious risk as phone thieves often compromise those devices.

Re: Ask HN: Gmail account security

#363
post #257

Earlier quoted context omitted.

> it is definitely doing non-trivial fingerprinting Can confirm. To generalize and understand why, big corps have to deal with an insane amount of (often automated) abuse, so they build profiles using data collection to assess your risk level. Being in the wrong cohort (say unusual browser, small country, rare language, use a vpn etc) can affect your score. Basically it's these massive bayesian filters that output ho…

> To generalize and understand why, big corps have to deal with an insane amount of (often automated) abuse, so they build profiles using data collection to assess your risk level. Total coincidence that it's also "you're not being a good little data source", I'm sure. I use a privacy-oriented browser on my cell phone to load amazon's website to get that stupid whole foods QR code for the checkout, because I'm not in…

> Total coincidence that it's also "you're not being a good little data source", I'm sure.

100% coincidental, of course :)

> that link is difficult to open in my preferred browser because iOS doesn't offer it as a choice for opening links...

Hmm, wasn't that fixed? Perhaps it's the email app that won't let you? I seem to be able to open many links in Firefox on iOS these days, but in some cases Safari is indeed the only option.

Re: Ask HN: Gmail account security

#364
post #197
post #77

Earlier quoted context omitted.

I have 2FA and a recovery email on my Gmail account, yet I have run into this issue. If Google thinks something is suspicious, it will decline your 2FA codes and recovery attempts—it will just tell you that you entered the wrong code. Only after you finally get back in do you find an email in your inbox explaining that the correct code was entered, but Google blocked it because it was suspicious. This happens to me f…

I think we need to quit calling it AI, and instead call it AS: Actual Stupidity

Or “Artificial Incompetence”

Re: Ask HN: Gmail account security

#365
post #324
post #278

I had this in ~2014 at an event. It literally would not let me log in no matter what. This did reinforce that running my own email server was a good idea. Like, what are you going to do if it actually is important? Call google support? I'd be surprised if they have a helpdesk with humans nowadays, let alone to fix some free account at 1am in the morning. Or even if you get to talk to a human, what are they going to d…

>Google thought the IP address was in Russia and I guess that makes it suspicious? (Feels a bit odd that entire countries are basically banned. I'm not sure why you immediately jumped to the conclusion that google is blocking entire countries. It seems fairly reasonable to block signins from russia if the account was created and has a history of signing in from another far-away country (eg. US). >Not as if criminals…

I'd be very surprised if I came to the US (not that I'd ever want to do that) and Google blocked my account there just because it is far away from my home location. People do travel, appearing far away is not uncommon, especially during a holiday season between Christmas and New Year's.

It didn't have a problem logging in with the same laptop from another place in Germany earlier that day. There are surely more factors, but the deciding one here seemed to be the geoip.

Perhaps anyone here can prove me wrong and confirm it's merely the distance that does it? Did anyone travel between two top ~50 HDI countries (not anything Google employees would consider putting on a blacklist, e.g. rich EU countries, Australia, USA, etc.) and had their login blocked with no way to access it?

Re: Ask HN: Gmail account security

#366
post #73
post #7

Wasn't aware of this, but can't say I'm surprised. Personally, I'm still happy with Fastmail, which uses customer subscriptions fees to fund a professional support department, as well as contributing to email-related FOSS. (Among other things, obviously.)

Fastmail looks great, but having "Get the email features you need, without giving up your privacy" and "Your data is always private" at the top of their homepage while knowing full well that is far from the case[0,1] seems disingenuous. [0] FastMail loses customers, faces calls to move over anti-encryption laws https://www.itnews.com.au/news/fastmail-loses-customers-face... [1] Goodbye FastMail https://www.ctrl.blog/…

I'm not expecting government-resistance from any third-party service.

Re: Ask HN: Gmail account security

#367

Earlier quoted context omitted.

A plug from a very satisfied customer: I pay $5/month for Fastmail. I've emailed support before and reached a human within hours. They helped me with my problem, because it was their job and I'm paying them to do it. Email is too important to rely on a free service which has a history of shutting people out, at any time, for any reason.

Just wanted to +1 this. I've been a happy customer of Fastmail since ~2013, never had a single issue, great service

> never had a single issue

Fastmail was blown offline by a couple of DDoS attacks recently. Both of them impacted my ability to access Fastmail, but I suppose you didn't happen to try to access your account during those attacks.

Re: Ask HN: Gmail account security

#368
post #7

Wasn't aware of this, but can't say I'm surprised. Personally, I'm still happy with Fastmail, which uses customer subscriptions fees to fund a professional support department, as well as contributing to email-related FOSS. (Among other things, obviously.)

Have you used Fastmail's support?

I have, yes, and the response was swift and helpful!

Re: Ask HN: Gmail account security

#369
post #257

Earlier quoted context omitted.

> it is definitely doing non-trivial fingerprinting Can confirm. To generalize and understand why, big corps have to deal with an insane amount of (often automated) abuse, so they build profiles using data collection to assess your risk level. Being in the wrong cohort (say unusual browser, small country, rare language, use a vpn etc) can affect your score. Basically it's these massive bayesian filters that output ho…

To clarify, these scores can be sanely used to decide what level of trust you have, and when you have none you get a capcha, a SMS check or something heavier to authorize the access you are trying to get. In my book you’re never supposed to fully block a session because of the score, there needs to be a (potentially burdensome) way to prove the score wrong. Blocking a browser should be out of question.

Even so, we still need to have a debate about what levels of "papieren bitte" we are willing to accept for different functions of society. The currently ubiquitous corporate-centric trend is to "nudge" instead of outright ban, i.e. instead of a bool it's numeric, and I highly doubt that the difference in data type is as significant as people think it is -- "Well you can always create a new account/buy another device/ask your friend to do it/.." and so on.

If these numeric scores are affecting search results, recommendations, when sharing stuff, etc etc, there's no question that it will affect societal discourse. These hidden "algorithms" (as in the popular term) and fraud prevention systems are so far from being understood that it may be too late to reverse it when we realize what's happened.

Re: Ask HN: Gmail account security

#370

Earlier quoted context omitted.

Its craziness all the way down. I have a google voice number which is my "default" number with my gmail accounts. All my gmail accounts were automatically migrated to use 2FA with this number which means if I lose all my google devices and I try to log into voice, I'll get 2FA I can't see because of the catch-22 situation of not being able to log into voice. The only reason I caught this is because they send me a not…

> Voice SMS is a mess too. 50% of services can't SMS it a code because Google blocks it. Other services won't accept it for SMS codes because its "not a real phone." The first part of that shouldn't be true. I've used mine to receive all kinds of SMS and it always works fine _except_ for the services that just won't accept the number. Only run across maybe one or two of those, over some years. For SMS from real peopl…

What happens is some organizations run a verifying to see if its a VOIP number, and if it is, considers it invalid for SMS based 2FA, and other authentication, presumably to stop hackers. Some big names use these lists, most notably Zelle to transfer money. Discord as well.

Why Google also seems to block incoming SMS from Microsoft Authentication and others is beyond me. Maybe MS isn't sending because it doesn't consider that number real and just fails silently on their end? Maybe Google's own lists are very aggressive. I suspect the latter because this comes up a lot. No one seems to have a good answer to any of this because there's no laws requiring transparency so they hide their rube-goldberg-esque SMS policies behind obscurity and its up to me, the customer, to somehow navigate this mess.

Yes, from regular people things are fine, but my life isn't dictated by regular people but the mega corporations capitalism creates and how I have to cater to their various technological whims. If my phone can't get messages because these big companies are always feuding in some way, then I'm locked out of essential services I need to live, have a job, do banking, etc. Its a small comfort that my friends can text me when I can't get texts from my bank, money transfers, or for work. As of right now in the USA, having a VOIP number be your primary phone number is unfeasible. I have a work cell with a "real" number that I use for at least 4 different services for SMS because of this issue.

Post reply on HN