Live data from Hacker News

Ask HN: Gmail account security

news.ycombinator.com

411–420 of 807 posts

Re: Ask HN: Gmail account security

#411
post #7

Wasn't aware of this, but can't say I'm surprised. Personally, I'm still happy with Fastmail, which uses customer subscriptions fees to fund a professional support department, as well as contributing to email-related FOSS. (Among other things, obviously.)

Fastmail's UI is just faster too.

IME, that's my biggest complaint. Even plain text emails take 2+ seconds to load.

Re: Ask HN: Gmail account security

#412
I've had this problem too.

In terms of security, it's great, but it's terrible when you're going back to old, dormant accounts and have lost trusted devices.

Thankfully, it's not a problem if you've set recovery emails and 2FA options, but it is easy to forget if the accounts are set up for someone else who isn't checking often (like family members who only use their accounts rarely)

It really takes months for the lockout to clear up, and it sucks when it happens.

Re: Ask HN: Gmail account security

#413
post #332

Earlier quoted context omitted.

I agree with the advice to get your own domain, and then use a service to manage email for it. But don't use GSuite/Google Workspaces/whatever they're calling it now. Your Google account will be somewhat crippled and will be missing a bunch of features, because Google has just decided GSuite accounts should not have those features. And you can't convert your account to a regular Google account. I really want to untan…

What features does GSuite lack?

Two that affect me: can't use it with Nest, can't buy family plan YouTube subs.

Re: Ask HN: Gmail account security

#414

Had this. It was telling me to try again 'later'. Ok, i did 'try later' every day for three weeks, and they didn't let me in. Using the very same IP address as I used to always access it, no less. Then, I gave up, moved all my services to another email account, and after 2 or 3 months tried logging in, and it suddenly allowed me to log in. Needless to say, I will never again use gmail for critically important things.

My solution is, buy your own domain. It's cheap and it will cost you only 20$ a year or something like that. I'm not saying run your own email service (I do, but I recognize that it's complex and not worth for most people), but use a public email service (like also GMail) with your own domain. That way at least if you no longer can access your account, or you get banned, or whatever, you don't loose your address (sin…

Won't work though, big email providers have made it a nightmare to run your own email.

Re: Ask HN: Gmail account security

#415
post #402

Earlier quoted context omitted.

Google sometimes blocks me from searching using Firefox, saying it’s “suspicious activity” and sending me into captcha hell that always rejects my results after several screens for no reason. It’s incredibly transparent as to what they’re doing. That Google became the most anti-consumer company out there is pretty disgraceful.

fake your browser header to a chrome variant.

That doesn't get rid of the problem, it only prolongs it.

Re: Ask HN: Gmail account security

#416
post #359

They have calculated that overall, a non-negligible amount of users will be hacked unless they have their system the way it is. Sure some accounts will get locked out, but overall it's a net benefit. There are hidden variables.

Based on what I see while consulting, I feel like more strange company behavior is attributed to cleverness than the real amount of stupidity/randomness that goes on. Here, too, there are so many variables and unknowns, this is not a calculable number. And even if they could, I am not sure they necessarily would. Bigcorps are not infallible and do not get everything correct with meticulous calculations on boatloads o…

The variables are hidden because the system would be insecure if they were known.

Re: Ask HN: Gmail account security

#417
The most insane thing is is not being able to sign in with the kind of 2FA you want until after you've signed in with a phone number.

This also affects paid Google Workspace accounts, which has a setting on GW to disable phone-based auth...

So you're stuck. you can't have people sign into 2FA until they do it via phone... and they can't do it via phone by security policy...

Just nuts.

Re: Ask HN: Gmail account security

#418
post #77
post #27

Earlier quoted context omitted.

> Needless to say, I will never again use gmail for critically important things. That's a hot take. If it was critically important, you'd have 2FA and a recovery phone number associated with it - which would have prevented you from getting stuck in a trust-fail situation to begin with. Use whatever service you want, but your takeaway from this situation is a bit absurd. Edit to add: I'm not saying Google's algorithm…

I have 2FA and a recovery email on my Gmail account, yet I have run into this issue. If Google thinks something is suspicious, it will decline your 2FA codes and recovery attempts—it will just tell you that you entered the wrong code. Only after you finally get back in do you find an email in your inbox explaining that the correct code was entered, but Google blocked it because it was suspicious. This happens to me f…

> If Google thinks something is suspicious, it will decline your 2FA codes and recovery attempts—it will just tell you that you entered the wrong code.

Seriously! What! The! Hell!

I too have thought before that having 2FA (and linking a phone number, which I hate to do) would avoid tripping in such situations and that the systems would consider a different situation (like a different IP address/location, a different browser) as reliable enough with 2FA. But this irks me a lot.

I don’t really use Gmail much and have other paid alternatives, but I have some old stuff that may be mildly inconvenient if I were to lose them. Need to download the data and dump these accounts.

Re: Ask HN: Gmail account security

#419
I have a 80+ old father. The security controls Google has put in place, I much appreciate them because he keeps a fairly simple password (but not one that is susceptible to dictionary attacks) and he cannot remember multiple passwords. I have tried using a password manager for him but he finds them too complicated. While I understand the pain this causes, any changes should accommodate the security and convenience of the older demographic.

Re: Ask HN: Gmail account security

#420
post #406

Earlier quoted context omitted.

You can do this with a regular Gmail account. The kid just can’t log into it until they are 13 or older. Google also now offers child Google accounts for kids under 13, which are limited and tied to a parent’s account through an app called Family Link. This is how you can set up a Chromebook for a kid, for example. This limit of age 13 is not arbitrary by Google; it’s their way of complying with a U.S. federal law ca…

It’s not arbitrary within the US, it’s arbitrary everywhere else, where the US law doesn’t apply.

Not when google is a US company.
Post reply on HN