Earlier quoted context omitted.
I have 2FA and a recovery email on my Gmail account, yet I have run into this issue. If Google thinks something is suspicious, it will decline your 2FA codes and recovery attempts—it will just tell you that you entered the wrong code. Only after you finally get back in do you find an email in your inbox explaining that the correct code was entered, but Google blocked it because it was suspicious. This happens to me f…
If we reason from good faith and consider that this is intentional and not a bug, have you considered that Google did not implement "blocking suspicious 2FA" just to mess with you? That perhaps this deals with a very real threat? Google has no incentive to make it difficult for you to log in, it's the exact opposite.
Ask HN: Gmail account security
421–430 of 807 posts
Re: Ask HN: Gmail account security
#422They also do this thing now where they block [1] smaller browsers (even ones using the latest version of chromium) under the guise of security. According to their docs they're fighting MITMs by generally disallowing any browser they can't identify (so the big few). If you're not on a whitelisted browser by Google, you can't log in (effectively, use) any of their properties. This feels very anti-competitive to me. Not…
> Notably all the whitelisted browsers are either theirs (Chrome) or sell them their search traffic. OK but that also describes pretty much all the Web browsers the vast majority of Web users actually intend to use, right?
Re: Ask HN: Gmail account security
#423Re: Ask HN: Gmail account security
#424They also do this thing now where they block [1] smaller browsers (even ones using the latest version of chromium) under the guise of security. According to their docs they're fighting MITMs by generally disallowing any browser they can't identify (so the big few). If you're not on a whitelisted browser by Google, you can't log in (effectively, use) any of their properties. This feels very anti-competitive to me. Not…
Interesting how the brand of security companies like Google keep telling us is in our best interests always seems to secure their corporate revenue streams first, while the security and freedom of users are an afterthought.
Re: Ask HN: Gmail account security
#425Earlier quoted context omitted.
You can do this with a regular Gmail account. The kid just can’t log into it until they are 13 or older. Google also now offers child Google accounts for kids under 13, which are limited and tied to a parent’s account through an app called Family Link. This is how you can set up a Chromebook for a kid, for example. This limit of age 13 is not arbitrary by Google; it’s their way of complying with a U.S. federal law ca…
It’s not arbitrary within the US, it’s arbitrary everywhere else, where the US law doesn’t apply.
Re: Ask HN: Gmail account security
#426They also do this thing now where they block [1] smaller browsers (even ones using the latest version of chromium) under the guise of security. According to their docs they're fighting MITMs by generally disallowing any browser they can't identify (so the big few). If you're not on a whitelisted browser by Google, you can't log in (effectively, use) any of their properties. This feels very anti-competitive to me. Not…
Hey, cool website !, The mailto: hyperlink on your careers button in the footer, has a typo, namely, "mailto:careers@synth.app&subject=Synth Careers&body=Please attach resume!" It should be, "mailto:careers@synth.app?subject=Synth Careers&body=Please attach resume!" that &subject instead of ?subject is causing that mailto link to not be imported properly by most mail apps, trivial thing, but thought I'd mention it. G…
Re: Ask HN: Gmail account security
#427Earlier quoted context omitted.
Google sometimes blocks me from searching using Firefox, saying it’s “suspicious activity” and sending me into captcha hell that always rejects my results after several screens for no reason. It’s incredibly transparent as to what they’re doing. That Google became the most anti-consumer company out there is pretty disgraceful.
fake your browser header to a chrome variant.
A faked header might look even more suspicious to their algorithm?
Re: Ask HN: Gmail account security
#428Re: Ask HN: Gmail account security
#429They also do this thing now where they block [1] smaller browsers (even ones using the latest version of chromium) under the guise of security. According to their docs they're fighting MITMs by generally disallowing any browser they can't identify (so the big few). If you're not on a whitelisted browser by Google, you can't log in (effectively, use) any of their properties. This feels very anti-competitive to me. Not…
Re: Ask HN: Gmail account security
#430Ha! We have to wait 24 hours after wrestling through the page, I leave my holiday visit in 36 hours, that's fine we have time I say to myself. A little odd but whatever, the account itself has no payment or important data associated with it really. 24 hours pass and the recovery page then suggests 14 days for recovery. What?!?! Why!?! (I mean, I get why, sort of, but I've done highly secure work that has less/shorter security processes than a consumer phone account). Apple says there's nothing they can do.
That's fine, well just create a new email and account for them I say to myself for their iPad annoying and yet another account for them to remember, lose the password, and deal with but whatever. Ok new email, new Apple account, sign in and perfect. Now I just need to disassociate the phone with the account its locked out of and switch it to the new Apple account to make syncing things a bit easier between devices. Wait, I can't do this until I recover the account to sign in to then log out of in the device. Wow. Again, I understand the security model here, but wow, a consumer device? Insanity.