One day I logged in to my Amazon account from a different country. Mind you, I have 2FA/OTP enabled in my account, and I entered it correctly. They also made me click on a link they sent via email to "verify my login". A couple hours later my account was blocked due to "suspicious login(s)" (i.e. mine), and the order I placed cancelled. They had me wait 24h until I could contact someone at support that could unblock…
Ask HN: Gmail account security
451–460 of 807 posts
Re: Ask HN: Gmail account security
#452Once upon a time I worked at Google. I returned to Austin to visit old friends and took the opportunity to visit the Google office there. The Googlers sitting around me were primarily corporate sales. They weren't getting any corporate sales calls at all as far as I could tell, but there was one extremely irate user who was locked out of their GMail account and was repeatedly calling them because they were the only h…
Re: Ask HN: Gmail account security
#453Earlier quoted context omitted.
I once had a situation where I didn't have access to my YubiKey but I had backup codes (not from the authenticator app but the 10 codes you are given when you set up 2FA for the first time). I could log in but I thought I'll remove the YubiKey from the account and set up TOTP (Authenticator) instead. It turns out you cannot do this using only backup codes, you have to have the key! So if you loose your key and run ou…
They do recommend having two keys associated with the account. It’s not cheap, but you can pick up a USB-C small format one and leave it in your computer & get one for your key ring that does NFC / Bluetooth. One is always with you, one is conveniently on your main computer. You can get the least expensive model as a third, off-site backup.
Re: Ask HN: Gmail account security
#454Had this. It was telling me to try again 'later'. Ok, i did 'try later' every day for three weeks, and they didn't let me in. Using the very same IP address as I used to always access it, no less. Then, I gave up, moved all my services to another email account, and after 2 or 3 months tried logging in, and it suddenly allowed me to log in. Needless to say, I will never again use gmail for critically important things.
Re: Ask HN: Gmail account security
#455Earlier quoted context omitted.
A browser environment designed for researching is something I've been investigating lately. I want to stay with Chromium for convenience (Chrome for work, ungoogled-chromium for personal). Right now I see two paths that might work for me: - A standalone browser that I use only for research purposes. Currently evaluating Bonsai [1] and am interested in Synth. - A suite of tools that makes bookmarking and organizing ea…
Awesome. To keep focus on the main topic, feel free to email me to chat more (FWIW I've done the 50 extension patchwork thing and generally find the extension experience to fractured and suboptimal for me).
Re: Ask HN: Gmail account security
#456Earlier quoted context omitted.
To clarify, these scores can be sanely used to decide what level of trust you have, and when you have none you get a capcha, a SMS check or something heavier to authorize the access you are trying to get. In my book you’re never supposed to fully block a session because of the score, there needs to be a (potentially burdensome) way to prove the score wrong. Blocking a browser should be out of question.
Even so, we still need to have a debate about what levels of "papieren bitte" we are willing to accept for different functions of society. The currently ubiquitous corporate-centric trend is to "nudge" instead of outright ban, i.e. instead of a bool it's numeric, and I highly doubt that the difference in data type is as significant as people think it is -- "Well you can always create a new account/buy another device/…
It seemed somewhat legitimate for a small free to use site mods to try to not get their whole life sunk by dealing with trolls, but if the same behavior is applied to giant entities who have much more incentives to do it at scale, it becomes a different issue altogether. Hidden restrictions on search results or other functionalities would be distopian and something I hope doesn’t get accepted as standard.
Re: Ask HN: Gmail account security
#457Earlier quoted context omitted.
Can you find a facebook engineer on LinkedIn and send them a InMail? Only costs you one month of linkedin plus, or whatever it is called.
I understand you are saying this in good faith, but honestly this is bullshit. Is the only way to get a solution to use LinkedIn inmail to solve a login crisis? There are plenty of FB engineers on this site alone. Are you all feeling okay with the work you’ve done?
1) Get your story on HN front page
2) Get a job at FB, fix issue yourself
3) Install Tinder, drive near FB offices, set search radius to minimum. Try to convince your matches to fix things
4) Buy a 0-day from the dark web, hack into FB and reset the password
5) Become incredibly wealthy, acrue enough FB stock to get a board seat, complain to the CEO
Re: Ask HN: Gmail account security
#458Earlier quoted context omitted.
Perhaps you'd have more luck using a Firefox Container instead.
Yes, FF Containers are ideal for this, or make a new Firefox profile altogether. Incognito windows don't preserve your cookies (that's the whole point of them) so the site has no way of "remembering" that device.
Re: Ask HN: Gmail account security
#459Arguable email addresses now are more important, that phone numbers. Mobile carriers are legally required to allow you to port numbers. We need a legal framework that allows to have inalienable email addresses.
Due to the decentralized nature of email, you can't have inalienable email addresses except within a domain. But you can register your own domain, and then, it is tied to your real identity and you can transfer it between registrars, which may be closer to what you had in mind. Most registrars provide an email relay, so that's probably the best you can get.
Re: Ask HN: Gmail account security
#460Not, Google, but I'm having sort of the same problem with Facebook. My church has a Facebook account that we used to set up our public page years ago. We assigned editors to the page, then promptly never used that account again. Fast forward to this year, and I need to add a new editor, which only the page admin can do. I reset the password on the church's facebook account (it was lost years ago), but when I log in,…
Can you find a facebook engineer on LinkedIn and send them a InMail? Only costs you one month of linkedin plus, or whatever it is called.