Live data from Hacker News

Ask HN: Gmail account security

news.ycombinator.com

441–450 of 807 posts

Re: Ask HN: Gmail account security

#441

Had this. It was telling me to try again 'later'. Ok, i did 'try later' every day for three weeks, and they didn't let me in. Using the very same IP address as I used to always access it, no less. Then, I gave up, moved all my services to another email account, and after 2 or 3 months tried logging in, and it suddenly allowed me to log in. Needless to say, I will never again use gmail for critically important things.

My solution is, buy your own domain. It's cheap and it will cost you only 20$ a year or something like that. I'm not saying run your own email service (I do, but I recognize that it's complex and not worth for most people), but use a public email service (like also GMail) with your own domain. That way at least if you no longer can access your account, or you get banned, or whatever, you don't loose your address (sin…

The only problem is now you have to make sure you dont get your domain hijacked. This was the reason I went back to gmail (and outlook).

Re: Ask HN: Gmail account security

#442
post #257

Earlier quoted context omitted.

> it is definitely doing non-trivial fingerprinting Can confirm. To generalize and understand why, big corps have to deal with an insane amount of (often automated) abuse, so they build profiles using data collection to assess your risk level. Being in the wrong cohort (say unusual browser, small country, rare language, use a vpn etc) can affect your score. Basically it's these massive bayesian filters that output ho…

To clarify, these scores can be sanely used to decide what level of trust you have, and when you have none you get a capcha, a SMS check or something heavier to authorize the access you are trying to get. In my book you’re never supposed to fully block a session because of the score, there needs to be a (potentially burdensome) way to prove the score wrong. Blocking a browser should be out of question.

Problem is that having an account be breached is catastrophic while getting locked out temporarily ranges from annoying to very annoying but not nearly as bad as having the account be breached. So if the filters have determined that someone is absolutely almost certainly a bot/attacker, it might make sense to do a total block like a bank would lock your account.

Unfortunately google doesn't have the support infrastructure like a bank to do recoveries.

Re: Ask HN: Gmail account security

#443
post #100

Earlier quoted context omitted.

1. In a thread about being locked out of google services because of AI black box, it makes sense to reduce dependence anywhere possible 2. If you get a new device, you need to un-enrol and re-enrol in all 2fa providers with g authenticator - it's a nightmare. Very hard if the old device got fatally dropped in a pool! I know at least with Authy you can carry the tokens to a new device.

I just want to chip in and say that 2. can be helped somewhat by having a second device (maybe old smartphone on wifi) that you export all authenticator keys to. Stick the old phone in a safe and make sure it's still working every so often (2x/year?) This is relatively new - a few years ago Authenticator did not support this. Oh, and make sure before you use the emergency device, time is synced - codes won't work oth…

> This is relatively new - a few years ago Authenticator did not support this.

Thanks, this was around when my device went for a swim.

Re: Ask HN: Gmail account security

#444
post #176

Earlier quoted context omitted.

Wow, that's awful. I wonder who's idea it was? Is it doing anything more than checking user agent (trivial to spoof), because if not that seems entirely hostile.

Likely the goal is to protect users from malicious apps, trying to get user to log in on a hosted browser component in order to scrape their data (or perform activities on behalf of user).

I think HN users often severely downplay the threats large companies are facing and frame every anti abuse measure as a coordinated attempt to shut down their indie browser fork.

People are having their lives ruined when their account gets breached which Google prioritizes over avoiding accidentally blocking a few odd users.

Re: Ask HN: Gmail account security

#445
Once upon a time I worked at Google.

I returned to Austin to visit old friends and took the opportunity to visit the Google office there. The Googlers sitting around me were primarily corporate sales.

They weren't getting any corporate sales calls at all as far as I could tell, but there was one extremely irate user who was locked out of their GMail account and was repeatedly calling them because they were the only human beings at Google the user was able to get in touch with, via something like "Press 3 for Corporate Sales." Of course these poor Google corporate sales people had absolutely no way to help this user even if they wanted to. Google literally did not have any GMail account phone support (at least at the time).

I could hear the poor guy screaming through their headsets about how he paid Google something for some service and was entitled to phone support and he demanded someone help him, but they just kept saying, "This is corporate sales. We do not offer consumer account support. If you want support, please visit the Google Support Forums at www dot..."

After they hung up on him 3 or 4 times, eventually a manager got on the phone and told him (between his screams), "Look, you're not getting any phone support because it doesn't exist. There's nowhere for us to transfer you. There's nobody who can call you back about this. Your only option is to search the forums for an answer to your problem. I am going to terminate this call now. Sir, I'm going to terminate this call. No, we can't help you. Nobody at Google can help you. I am terminating this call now. We asked you to stop calling this number. Do not call us again. "

I'd frequently tell my co-workers, "If you're not paying for it, you're the product." That experience underscored that notion for me.

Re: Ask HN: Gmail account security

#446
post #287

Earlier quoted context omitted.

I did this! Kind of. I bought a domain and was lucky enough to get in to a custom domain email (and more) service with a big company years ago when they had a free version. Unfortunately... it was Google (so kind of hiring the wolf to care for my sheep, as it turns out). And now they're cutting off all of us free tier folks. Which I can't fault them for, but still blame them for. Because I'm petty and entitled or wha…

Same situation here. Have you done the research yet to decide on a new service, or are you planning on starting to pay? For me ideally I would like to move to something else (even paid) just because someday Google deciding to block me for whatever reason scares me quite a bit after having everything for the last decade attached to this account. I would like to export my emails, switch my domain to the new service, an…

I switched to Apple's (paid) iCloud+(?) and it was entirely smooth, even though it was still in beta at the time (or alpha: the signup notification I got still had editorial comments in it).

Re: Ask HN: Gmail account security

#447

Yep, and it was even more aggravating. > have three gmail accounts > primary, name.surname@gmail.com > secondary, name.surname.purchases@gmail.com > tertiary, name.surname.work@gmail.com > secondary and tertiary have primary as a recovery address > log in/out once a week in 2nd and 3rd > last August, try to log into name.surname.work > "Password is incorrect" > WTH?! of course it's correct. > try several times, Googl…

Perhaps you're not supposed to have more than 1 gmail account, and the assumptions in their code cannot deal with more than 1 account per user, or worse, they actively try to discourage it.

This would be pretty foolish on their end to discriminate this way, because I'm willing to bet 99% of their enterprise customers employees also have personal gmail accounts.

Re: Ask HN: Gmail account security

#449
Years ago, but just after Google purchased YouTube, I forgot my YouTube password so they emailed it to me in plaintext.

Maybe 10 years ago I experienced forgotten Gmail password hell when a family member forgot their password and was never able to recover the account.

Can't wait to see what the process is like another 10 years from now.

Re: Ask HN: Gmail account security

#450
post #97

Just FYI there is a solution to this: enroll your gmail account in the advanced protection program https://landing.google.com/advancedprotection/ When you login you are required to use a security key (like Yubi key) but it removes all the annoying emails and texts with codes, IP filtering, login AI, etc

If you use your phone as the security key and something goes wrong you are in exactly the same situation. Let alone with weird one where they talk to your phone using bluetooth as a security key. I have seen that one go very wrong so many times now.
Post reply on HN