Live data from Hacker News

Ask HN: Gmail account security

news.ycombinator.com

451–460 of 807 posts

Re: Ask HN: Gmail account security

#451

One day I logged in to my Amazon account from a different country. Mind you, I have 2FA/OTP enabled in my account, and I entered it correctly. They also made me click on a link they sent via email to "verify my login". A couple hours later my account was blocked due to "suspicious login(s)" (i.e. mine), and the order I placed cancelled. They had me wait 24h until I could contact someone at support that could unblock…

2FA is going to be exposed badly by some basic social engineering one day. When I worked in a hospital, 99% of the people dealing with HIPAA protected patient data were doing so on a desktop that sits in an unlocked office or in an open reception area with the duo two factor authentication set to call the landline right next to the desktop.

Re: Ask HN: Gmail account security

#452

Once upon a time I worked at Google. I returned to Austin to visit old friends and took the opportunity to visit the Google office there. The Googlers sitting around me were primarily corporate sales. They weren't getting any corporate sales calls at all as far as I could tell, but there was one extremely irate user who was locked out of their GMail account and was repeatedly calling them because they were the only h…

Was the screaming guy no paying for some service?

Re: Ask HN: Gmail account security

#453
post #241
post #169

Earlier quoted context omitted.

I once had a situation where I didn't have access to my YubiKey but I had backup codes (not from the authenticator app but the 10 codes you are given when you set up 2FA for the first time). I could log in but I thought I'll remove the YubiKey from the account and set up TOTP (Authenticator) instead. It turns out you cannot do this using only backup codes, you have to have the key! So if you loose your key and run ou…

They do recommend having two keys associated with the account. It’s not cheap, but you can pick up a USB-C small format one and leave it in your computer & get one for your key ring that does NFC / Bluetooth. One is always with you, one is conveniently on your main computer. You can get the least expensive model as a third, off-site backup.

All hardware dies at some point. What if both the Yubikeys die? What if the third one was already dead before and it wasn’t noticed because it wasn’t used recently? This sounds like too deep a maze for I don’t know how much benefit.

Re: Ask HN: Gmail account security

#454

Had this. It was telling me to try again 'later'. Ok, i did 'try later' every day for three weeks, and they didn't let me in. Using the very same IP address as I used to always access it, no less. Then, I gave up, moved all my services to another email account, and after 2 or 3 months tried logging in, and it suddenly allowed me to log in. Needless to say, I will never again use gmail for critically important things.

Had the same thing happen to me, I know the password, have access to the recovery email but Google won't let me login. Spent months in a support thread with Google and eventually gave up. Still really bummed about it tbh

Re: Ask HN: Gmail account security

#455

Earlier quoted context omitted.

A browser environment designed for researching is something I've been investigating lately. I want to stay with Chromium for convenience (Chrome for work, ungoogled-chromium for personal). Right now I see two paths that might work for me: - A standalone browser that I use only for research purposes. Currently evaluating Bonsai [1] and am interested in Synth. - A suite of tools that makes bookmarking and organizing ea…

Awesome. To keep focus on the main topic, feel free to email me to chat more (FWIW I've done the 50 extension patchwork thing and generally find the extension experience to fractured and suboptimal for me).

What OSes are compatible?

Re: Ask HN: Gmail account security

#456
post #369

Earlier quoted context omitted.

To clarify, these scores can be sanely used to decide what level of trust you have, and when you have none you get a capcha, a SMS check or something heavier to authorize the access you are trying to get. In my book you’re never supposed to fully block a session because of the score, there needs to be a (potentially burdensome) way to prove the score wrong. Blocking a browser should be out of question.

Even so, we still need to have a debate about what levels of "papieren bitte" we are willing to accept for different functions of society. The currently ubiquitous corporate-centric trend is to "nudge" instead of outright ban, i.e. instead of a bool it's numeric, and I highly doubt that the difference in data type is as significant as people think it is -- "Well you can always create a new account/buy another device/…

I agree with you. I think this discussion started around the time shadowbanning was gradually used on forums to reduce moderation workload.

It seemed somewhat legitimate for a small free to use site mods to try to not get their whole life sunk by dealing with trolls, but if the same behavior is applied to giant entities who have much more incentives to do it at scale, it becomes a different issue altogether. Hidden restrictions on search results or other functionalities would be distopian and something I hope doesn’t get accepted as standard.

Re: Ask HN: Gmail account security

#457
post #401

Earlier quoted context omitted.

Can you find a facebook engineer on LinkedIn and send them a InMail? Only costs you one month of linkedin plus, or whatever it is called.

I understand you are saying this in good faith, but honestly this is bullshit. Is the only way to get a solution to use LinkedIn inmail to solve a login crisis? There are plenty of FB engineers on this site alone. Are you all feeling okay with the work you’ve done?

There’s plenty of ways:

1) Get your story on HN front page

2) Get a job at FB, fix issue yourself

3) Install Tinder, drive near FB offices, set search radius to minimum. Try to convince your matches to fix things

4) Buy a 0-day from the dark web, hack into FB and reset the password

5) Become incredibly wealthy, acrue enough FB stock to get a board seat, complain to the CEO

Re: Ask HN: Gmail account security

#458

Earlier quoted context omitted.

Perhaps you'd have more luck using a Firefox Container instead.

Yes, FF Containers are ideal for this, or make a new Firefox profile altogether. Incognito windows don't preserve your cookies (that's the whole point of them) so the site has no way of "remembering" that device.

I'll have to give that a shot. Thank you both!

Re: Ask HN: Gmail account security

#459

Arguable email addresses now are more important, that phone numbers. Mobile carriers are legally required to allow you to port numbers. We need a legal framework that allows to have inalienable email addresses.

Or government issued email addresses tied to your identity, either as a citizen or as a registered company.

Due to the decentralized nature of email, you can't have inalienable email addresses except within a domain. But you can register your own domain, and then, it is tied to your real identity and you can transfer it between registrars, which may be closer to what you had in mind. Most registrars provide an email relay, so that's probably the best you can get.

Re: Ask HN: Gmail account security

#460
post #401

Not, Google, but I'm having sort of the same problem with Facebook. My church has a Facebook account that we used to set up our public page years ago. We assigned editors to the page, then promptly never used that account again. Fast forward to this year, and I need to add a new editor, which only the page admin can do. I reset the password on the church's facebook account (it was lost years ago), but when I log in,…

Can you find a facebook engineer on LinkedIn and send them a InMail? Only costs you one month of linkedin plus, or whatever it is called.

If it would work, then 100% I would do it in a heartbeat. I posted on Blind looking for help, but just got snarky high-school level comments. Have you had experience reaching out via LinkedIn?
Post reply on HN