Live data from Hacker News

Ask HN: Gmail account security

news.ycombinator.com

421–430 of 807 posts

Re: Ask HN: Gmail account security

#421
post #174
post #77

Earlier quoted context omitted.

I have 2FA and a recovery email on my Gmail account, yet I have run into this issue. If Google thinks something is suspicious, it will decline your 2FA codes and recovery attempts—it will just tell you that you entered the wrong code. Only after you finally get back in do you find an email in your inbox explaining that the correct code was entered, but Google blocked it because it was suspicious. This happens to me f…

If we reason from good faith and consider that this is intentional and not a bug, have you considered that Google did not implement "blocking suspicious 2FA" just to mess with you? That perhaps this deals with a very real threat? Google has no incentive to make it difficult for you to log in, it's the exact opposite.

I agree to some extent, but also consider that whoever designed this may not be as intelligent or as widely experienced in certain matters as is necessary for the real world.

Re: Ask HN: Gmail account security

#422
post #67

They also do this thing now where they block [1] smaller browsers (even ones using the latest version of chromium) under the guise of security. According to their docs they're fighting MITMs by generally disallowing any browser they can't identify (so the big few). If you're not on a whitelisted browser by Google, you can't log in (effectively, use) any of their properties. This feels very anti-competitive to me. Not…

> Notably all the whitelisted browsers are either theirs (Chrome) or sell them their search traffic. OK but that also describes pretty much all the Web browsers the vast majority of Web users actually intend to use, right?

Yes, in part thanks to their efforts to make it harder to use other browsers...

Re: Ask HN: Gmail account security

#423
Arguable email addresses now are more important, that phone numbers. Mobile carriers are legally required to allow you to port numbers. We need a legal framework that allows to have inalienable email addresses.

Re: Ask HN: Gmail account security

#424
post #67

They also do this thing now where they block [1] smaller browsers (even ones using the latest version of chromium) under the guise of security. According to their docs they're fighting MITMs by generally disallowing any browser they can't identify (so the big few). If you're not on a whitelisted browser by Google, you can't log in (effectively, use) any of their properties. This feels very anti-competitive to me. Not…

Interesting how the brand of security companies like Google keep telling us is in our best interests always seems to secure their corporate revenue streams first, while the security and freedom of users are an afterthought.

Yeah, they make almost tens of dollars forcing users to use Safari or Edge instead of lynx.

Re: Ask HN: Gmail account security

#425
post #406

Earlier quoted context omitted.

You can do this with a regular Gmail account. The kid just can’t log into it until they are 13 or older. Google also now offers child Google accounts for kids under 13, which are limited and tied to a parent’s account through an app called Family Link. This is how you can set up a Chromebook for a kid, for example. This limit of age 13 is not arbitrary by Google; it’s their way of complying with a U.S. federal law ca…

It’s not arbitrary within the US, it’s arbitrary everywhere else, where the US law doesn’t apply.

Google is a US company so US law always applies to it.

Re: Ask HN: Gmail account security

#426
post #67

They also do this thing now where they block [1] smaller browsers (even ones using the latest version of chromium) under the guise of security. According to their docs they're fighting MITMs by generally disallowing any browser they can't identify (so the big few). If you're not on a whitelisted browser by Google, you can't log in (effectively, use) any of their properties. This feels very anti-competitive to me. Not…

Hey, cool website !, The mailto: hyperlink on your careers button in the footer, has a typo, namely, "mailto:careers@synth.app&subject=Synth Careers&body=Please attach resume!" It should be, "mailto:careers@synth.app?subject=Synth Careers&body=Please attach resume!" that &subject instead of ?subject is causing that mailto link to not be imported properly by most mail apps, trivial thing, but thought I'd mention it. G…

And replacing the spaces in the subject with %20 will fix it on more browsers, at least it's at the end :)

Re: Ask HN: Gmail account security

#427
post #402

Earlier quoted context omitted.

Google sometimes blocks me from searching using Firefox, saying it’s “suspicious activity” and sending me into captcha hell that always rejects my results after several screens for no reason. It’s incredibly transparent as to what they’re doing. That Google became the most anti-consumer company out there is pretty disgraceful.

fake your browser header to a chrome variant.

The header isn't the only thing that identifies a browser.

A faked header might look even more suspicious to their algorithm?

Re: Ask HN: Gmail account security

#429
post #67

They also do this thing now where they block [1] smaller browsers (even ones using the latest version of chromium) under the guise of security. According to their docs they're fighting MITMs by generally disallowing any browser they can't identify (so the big few). If you're not on a whitelisted browser by Google, you can't log in (effectively, use) any of their properties. This feels very anti-competitive to me. Not…

I wonder if that takes long for gogle to create a premium search account product. Paid one.

Re: Ask HN: Gmail account security

#430
From my experience, as a non-Apple user, they are the absolute worst. I bought a family member an iPad for Christmas. They had an Apple account associated with their iPhone. They forgot their password. No big deal, I'll just reset their password.

Ha! We have to wait 24 hours after wrestling through the page, I leave my holiday visit in 36 hours, that's fine we have time I say to myself. A little odd but whatever, the account itself has no payment or important data associated with it really. 24 hours pass and the recovery page then suggests 14 days for recovery. What?!?! Why!?! (I mean, I get why, sort of, but I've done highly secure work that has less/shorter security processes than a consumer phone account). Apple says there's nothing they can do.

That's fine, well just create a new email and account for them I say to myself for their iPad annoying and yet another account for them to remember, lose the password, and deal with but whatever. Ok new email, new Apple account, sign in and perfect. Now I just need to disassociate the phone with the account its locked out of and switch it to the new Apple account to make syncing things a bit easier between devices. Wait, I can't do this until I recover the account to sign in to then log out of in the device. Wow. Again, I understand the security model here, but wow, a consumer device? Insanity.

Post reply on HN