Live data from Hacker News

Ask HN: Gmail account security

news.ycombinator.com

591–600 of 807 posts

Re: Ask HN: Gmail account security

#591
post #499
post #495

Earlier quoted context omitted.

Disclaimer. I'm a new Google play thing, by giving them money. Just registered a website through them and am about to release a game on the playstore. Fully dependant on zero custom service now. The one thing I've never understood about google. Some sort of law for a trillion dollar company to have customer service or something. Google should be employing 10's of thousands of customer service employees to take calls…

More laws aren’t always the answer. Really, we should just be using a company that gives a shit about its users.

Because that worked so well in the past. There is no "we" - they wouldn't have become a billion dollar company if they hadn't found ways to make people still use them despite those issues.

But that doesn't mean they aren't issues.

Re: Ask HN: Gmail account security

#592

What piss me off the most with Gmail and google things like meet, is that if you are on Android, there is no way to login in a single app: Gmail, meet or even a third party email app without associating your Google account to the whole phone. This is really annoying. Sometimes I have to join corporate meeting from my personal email account on my personal phone, because if I would like to login with my pro one, all my…

FWIW android supports Work profiles for exactly this purpose (though your company may not allow them). So for example I have my work and personal accounts on my phone, and my employer (Google in this case) can manage my work profile, up to and including erasing data on it, but can't do anything to my personal accounts.

Still, you will have to associate all your phone with this account to use a single app. Like search and all. That would not make sense if android was not tied to Google.

Re: Ask HN: Gmail account security

#593
Last time I had to deal with Google's account recovery (10 years ago when my mom fell for a phishing scam) there was an option to pay a few dollars to get to talk to a real human in a customer service / operations department. Does that still exist?

Re: Ask HN: Gmail account security

#594
post #451

One day I logged in to my Amazon account from a different country. Mind you, I have 2FA/OTP enabled in my account, and I entered it correctly. They also made me click on a link they sent via email to "verify my login". A couple hours later my account was blocked due to "suspicious login(s)" (i.e. mine), and the order I placed cancelled. They had me wait 24h until I could contact someone at support that could unblock…

2FA is going to be exposed badly by some basic social engineering one day. When I worked in a hospital, 99% of the people dealing with HIPAA protected patient data were doing so on a desktop that sits in an unlocked office or in an open reception area with the duo two factor authentication set to call the landline right next to the desktop.

HIPAA is always going to be a joke. Walk around the hospital's parking lot and drop a bunch of malicious USB drives with the logo of the hospital on them. Someone is bound to pick one up and stick it in a machine on the network.

Re: Ask HN: Gmail account security

#595

Earlier quoted context omitted.

Google sometimes blocks me from searching using Firefox, saying it’s “suspicious activity” and sending me into captcha hell that always rejects my results after several screens for no reason. It’s incredibly transparent as to what they’re doing. That Google became the most anti-consumer company out there is pretty disgraceful.

I use google constantly— sometimes hundreds of times per day— both logged in and out, almost exclusively in Firefox or Firefox developer edition and I've never encountered this. I'd bank on it being a network thing— VPN, overcrowded proxy, etc.

I get it ln firefox without a VPN with my own IP owner by a reputable ISP. On a pixel phone with google DNS.

On a VPN I do not get it, so the last couple of weeks I have been making heavy use of my mullvad account.

Edit: however. I only store cookies for fastmail and hacker news and do not allow JS on many sites.

Re: Ask HN: Gmail account security

#596
post #268

Earlier quoted context omitted.

Yeah this sounds like utter bullshit to me. What if you're travelling, all your devices get stolen, and you're logging in from a public computer or friend's computer to contact your family? This is mindblowingly idiotic. Do they have such a bad vacation policy for their employees that not a single ONE of their engineering managers has experienced the above? Do they just sit in front of their desks for 365 days a year…

My guess is they get defrauded more often. The scenario you present is a really obvious risk as phone thieves often compromise those devices.

No, I think it's a huge risk to be stuck somewhere these days without any means of contacting your family or getting emergency money sent to you. Especially if you're in a place that's politically unstable or where helping strangers isn't the norm.

One of these days someone will not be able to get their heart medications or a flight home because of this damn Gmail policy.

Re: Ask HN: Gmail account security

#598

Earlier quoted context omitted.

I guess this is why Amazon is playing the long game with their obsessive focus on customers. I don't know how that really plays out where the rubber meets the road but that's what Jeff bezos always keeps talking about.

I worked at both Amazon and Google. It was only at Amazon where I was exposed to the Craft of software development. Personally, I feel there is a nuanced difference to the role at Amazon being SDE ( Software Development Engineer ) whereas Google is SWE ( Software Engineer ). It's almost like Google thinks Software Developers are lower tier than Software Engineers, but I'd like to think of myself as doing more than ju…

Interesting take. It sounds like you really dislike Google. It also sounds like your manager had something to do with it. Perhaps it was a lack of promotion?

Since you’ve worked at both, do you have an opinion on why protocol buffers aren’t more widely adopted than json?

Re: Ask HN: Gmail account security

#599
post #7

Wasn't aware of this, but can't say I'm surprised. Personally, I'm still happy with Fastmail, which uses customer subscriptions fees to fund a professional support department, as well as contributing to email-related FOSS. (Among other things, obviously.)

Have you used Fastmail's support?

Yes - it was almost instantaneous, super helpful.

Re: Ask HN: Gmail account security

#600
post #67

They also do this thing now where they block [1] smaller browsers (even ones using the latest version of chromium) under the guise of security. According to their docs they're fighting MITMs by generally disallowing any browser they can't identify (so the big few). If you're not on a whitelisted browser by Google, you can't log in (effectively, use) any of their properties. This feels very anti-competitive to me. Not…

Google sometimes blocks me from searching using Firefox, saying it’s “suspicious activity” and sending me into captcha hell that always rejects my results after several screens for no reason. It’s incredibly transparent as to what they’re doing. That Google became the most anti-consumer company out there is pretty disgraceful.

Is it possible that your requests are coming from an IP address that google has flagged for previous abuse? I think that the "suspicious activity" captcha hell is triggered by a high request volume from multiple not-logged-in agents on the same IP. At least that's been my experience in the past.
Post reply on HN