Live data from Hacker News

Ask HN: Gmail account security

news.ycombinator.com

521–530 of 807 posts

Re: Ask HN: Gmail account security

#521
post #67

They also do this thing now where they block [1] smaller browsers (even ones using the latest version of chromium) under the guise of security. According to their docs they're fighting MITMs by generally disallowing any browser they can't identify (so the big few). If you're not on a whitelisted browser by Google, you can't log in (effectively, use) any of their properties. This feels very anti-competitive to me. Not…

How do we get our embedded webview driven app verified as a secure browser or has the AI already designated the lucky few and we are cast aside?

Re: Ask HN: Gmail account security

#522
What piss me off the most with Gmail and google things like meet, is that if you are on Android, there is no way to login in a single app: Gmail, meet or even a third party email app without associating your Google account to the whole phone.

This is really annoying. Sometimes I have to join corporate meeting from my personal email account on my personal phone, because if I would like to login with my pro one, all my personal phone will be associated and controllable by the company.

Re: Ask HN: Gmail account security

#523
post #499
post #495

Earlier quoted context omitted.

Disclaimer. I'm a new Google play thing, by giving them money. Just registered a website through them and am about to release a game on the playstore. Fully dependant on zero custom service now. The one thing I've never understood about google. Some sort of law for a trillion dollar company to have customer service or something. Google should be employing 10's of thousands of customer service employees to take calls…

More laws aren’t always the answer. Really, we should just be using a company that gives a shit about its users.

Problem is it all works just fine until you get locked out and have no options. So the market won't ever gradually move over because its only a very small % who get hit with an awful experience while everyone else is perfectly fine.

Re: Ask HN: Gmail account security

#524
post #470

Earlier quoted context omitted.

You are actually pointing out a tremendous opportunity that Google has internally and externally. I work at Google and recently tried to file a bug about the calculator embedded in search. It was dastardly difficult to find how to file the ticket. It took me maybe an hour. A better system for filing tickets internally and for filing and triaging tickets from external users would be a tremendous asset for Google.

Did GUTS not survive? When I left, it was pretty solid. Some very close friends of mine spent years on that system. Haven't thought about it in a while but it was so simple and easy. Then again, that was a decade ago.

GUTS is still used for things like desk moves, but buganizer is where eng tickets live. (at least when I left a few years ago)

Re: Ask HN: Gmail account security

#525
post #511

This is because most people use Gmail for basically all their online accounts: if you don't directly login to the site via Gmail, you can use your account to change your password. Imagine the damage which can be done if a malicious user breaks into someone's Gmail, if not your own, then the average person who uses the same password everywhere and trusts Gmail with everything. Not defending the practice at all. It sho…

> obviously if someone can authenticate with a YubiKey they are practically guaranteed to be the real person. Or someone grabbed your backpack. I understand why Google wants 2FA - it gives them a stronger claim to not provide support. Personally I don't want 2FA - I use strong passwords, and I don't trust them to provide support if my device is lost. Imagine a house fire, for instance, and losing not only your posses…

The chance of someone stealing your physical token, and knowing your email + password are almost impossibly low.

Re: Ask HN: Gmail account security

#526
post #67

They also do this thing now where they block [1] smaller browsers (even ones using the latest version of chromium) under the guise of security. According to their docs they're fighting MITMs by generally disallowing any browser they can't identify (so the big few). If you're not on a whitelisted browser by Google, you can't log in (effectively, use) any of their properties. This feels very anti-competitive to me. Not…

Godspeed building any browser. I know it's just for research, but I miss options. Palemoon was great until it imploded.

Re: Ask HN: Gmail account security

#527
post #287

Earlier quoted context omitted.

I did this! Kind of. I bought a domain and was lucky enough to get in to a custom domain email (and more) service with a big company years ago when they had a free version. Unfortunately... it was Google (so kind of hiring the wolf to care for my sheep, as it turns out). And now they're cutting off all of us free tier folks. Which I can't fault them for, but still blame them for. Because I'm petty and entitled or wha…

Same situation here. Have you done the research yet to decide on a new service, or are you planning on starting to pay? For me ideally I would like to move to something else (even paid) just because someday Google deciding to block me for whatever reason scares me quite a bit after having everything for the last decade attached to this account. I would like to export my emails, switch my domain to the new service, an…

I’ve been really happy with ProtonMail. I use their professional account with a catch-all email address on my domain, and I give each vendor I interact with their own dedicated email address (I.e. homedepot@mydomain.com, ticketmaster@mydomain.com, etc.)

It lets me track who is sharing my email address and gives me control over that (set up simple filter to automatically delete any email received at ticketmaster@mydomain.com when I start getting spam on it).

It’s been really effective - such a part of my day-to-day flow now I can’t go back.

The transition was pretty painless. I setup an email forward from gmail to my proton inbox using gmail@mydomain.com, every email I received at that address I’d go update my contact information with. After a bit, I was able to turn off the forwarding. Basically the classic strangulation pattern for microservice migrations applied to email.

Re: Ask HN: Gmail account security

#528

From my experience, as a non-Apple user, they are the absolute worst. I bought a family member an iPad for Christmas. They had an Apple account associated with their iPhone. They forgot their password. No big deal, I'll just reset their password. Ha! We have to wait 24 hours after wrestling through the page, I leave my holiday visit in 36 hours, that's fine we have time I say to myself. A little odd but whatever, the…

The problem is the Apple ID is heavily tied in to their anti theft features. So you just cant reset a device without the password. And people do not understand the gravity of this situation, someone at the Apple store really should be hammering it in that you must not ever lose your Apple ID password.

Re: Ask HN: Gmail account security

#529
I've lost several paying business accounts to this problem because I never log in except when a credit card expires and then I need to update it with a new one. By that point I've moved or changed computers or ISPs or something and there's no way to 'identify' me anymore.

Re: Ask HN: Gmail account security

#530
post #457

Earlier quoted context omitted.

I understand you are saying this in good faith, but honestly this is bullshit. Is the only way to get a solution to use LinkedIn inmail to solve a login crisis? There are plenty of FB engineers on this site alone. Are you all feeling okay with the work you’ve done?

There’s plenty of ways: 1) Get your story on HN front page 2) Get a job at FB, fix issue yourself 3) Install Tinder, drive near FB offices, set search radius to minimum. Try to convince your matches to fix things 4) Buy a 0-day from the dark web, hack into FB and reset the password 5) Become incredibly wealthy, acrue enough FB stock to get a board seat, complain to the CEO

Someone should sell VPN exit nodes next to BigTech offices so that people can exit their Tinder there and do the (3) connection approach without the drive.
Post reply on HN