Live data from Hacker News

Ask HN: Gmail account security

news.ycombinator.com

691–700 of 807 posts

Re: Ask HN: Gmail account security

#691
post #470

Earlier quoted context omitted.

You are actually pointing out a tremendous opportunity that Google has internally and externally. I work at Google and recently tried to file a bug about the calculator embedded in search. It was dastardly difficult to find how to file the ticket. It took me maybe an hour. A better system for filing tickets internally and for filing and triaging tickets from external users would be a tremendous asset for Google.

Maybe they don't want you to file the bug too easily? I imagine Google would getting 10,000s bugs per day if it was too easy.

I'd rather know where my ship is burning instead of closing my eyes and just having happy thoughts.

But then, I am an engineer, not some marketing drone...

Re: Ask HN: Gmail account security

#692

Once upon a time I worked at Google. I returned to Austin to visit old friends and took the opportunity to visit the Google office there. The Googlers sitting around me were primarily corporate sales. They weren't getting any corporate sales calls at all as far as I could tell, but there was one extremely irate user who was locked out of their GMail account and was repeatedly calling them because they were the only h…

Even when you have paid Google products that come with support, it is really awful. They once asked me to submit a business case justifying how answering my support question benefited Google. Just a simple clarification of something in their documentation. I was already under pressure to migrate to Office360, I stopped fighting after that. My employer is a huge AWS user and Google is constantly chasing us with a trea…

> Even when you have paid Google products that come with support, it is really awful

Once I subscribed to YouTube Music (paid!) family plan, but my wife's account would always say that she is in another country and can not join the plan. I tried everything - the support never even bothered to reply to my emails. I cancelled the plan and since then I keep seeing the same ads for the premium service every time I open the YT mobile app.

Re: Ask HN: Gmail account security

#693

Earlier quoted context omitted.

I work at a company with >1000 google workspace users. That's enough that someone at Google will acknowledge what you're reporting is a bug on their end, and that they can reproduce it. But it's not enough to get the bug fixed. The support may be good if you're asking questions they've heard before - or if you need something like an account lock reset, which the support folks have a button for. But if the problem you…

I’m sure that in the mind of Google they are doing a favor by letting us give them money, wanting support is just ungrateful. Wanting a bug fix is just obscene. They have 150,000 PhDs, aren’t we bold to question them!

Turns out, having a PhD is a negative when it comes to closing bugs.

Re: Ask HN: Gmail account security

#694

Earlier quoted context omitted.

Even when you have paid Google products that come with support, it is really awful. They once asked me to submit a business case justifying how answering my support question benefited Google. Just a simple clarification of something in their documentation. I was already under pressure to migrate to Office360, I stopped fighting after that. My employer is a huge AWS user and Google is constantly chasing us with a trea…

> Even when you have paid Google products that come with support, it is really awful Once I subscribed to YouTube Music (paid!) family plan, but my wife's account would always say that she is in another country and can not join the plan. I tried everything - the support never even bothered to reply to my emails. I cancelled the plan and since then I keep seeing the same ads for the premium service every time I open t…

FWIW I had the same problem a few months ago, and they did eventually sort me out. This surprised me, given Google's reputation. I was on the 1-month "free trial" membership, and always planned to switch to the single-person membership if they didn't get it sorted out, so I wasn't really out any money during that time.

(And in fact, what actually happened was they hadn't sorted me out by the time the free trial was up, so I cancelled it and switched to the individual membership. They managed to get things sorted out a week or two after that, but I'm still on the individual membership; my wife just shares my account ID.)

Re: Ask HN: Gmail account security

#695
post #7

Wasn't aware of this, but can't say I'm surprised. Personally, I'm still happy with Fastmail, which uses customer subscriptions fees to fund a professional support department, as well as contributing to email-related FOSS. (Among other things, obviously.)

I too have used Fastmail for over a year now, but I do wish they would add a few much needed features.

Re: Ask HN: Gmail account security

#696

Earlier quoted context omitted.

I've first hand experience with managing a google workspace (50 users) and an Azure AD (30 users). With google workspace, the chat is two click away and the guys now their stuff. With Azure AD, no support, no chat, except "here is a list of consultant in your area that provide support". And I pay twice as much to microsoft ...

I work at a company with >1000 google workspace users. That's enough that someone at Google will acknowledge what you're reporting is a bug on their end, and that they can reproduce it. But it's not enough to get the bug fixed. The support may be good if you're asking questions they've heard before - or if you need something like an account lock reset, which the support folks have a button for. But if the problem you…

That must have been fixed. I got a message to enable third party cookies for drive.google.com. Even with a link to docs on how to do it iirc.

Re: Ask HN: Gmail account security

#697

Had this. It was telling me to try again 'later'. Ok, i did 'try later' every day for three weeks, and they didn't let me in. Using the very same IP address as I used to always access it, no less. Then, I gave up, moved all my services to another email account, and after 2 or 3 months tried logging in, and it suddenly allowed me to log in. Needless to say, I will never again use gmail for critically important things.

My solution is, buy your own domain. It's cheap and it will cost you only 20$ a year or something like that. I'm not saying run your own email service (I do, but I recognize that it's complex and not worth for most people), but use a public email service (like also GMail) with your own domain. That way at least if you no longer can access your account, or you get banned, or whatever, you don't loose your address (sin…

Honestly i really like Gmail as a client, but I've read too many Google horror stories over the years. Therefore I've always had this setup: own domain & mailbox at a trusty provider, and then just forwarding copies to a gmail account + sending via smtp

that way I've got the comfort of gmails features but always have a "real" mailbox to fall back to if anything happens

Re: Ask HN: Gmail account security

#698

Earlier quoted context omitted.

I work at a company with >1000 google workspace users. That's enough that someone at Google will acknowledge what you're reporting is a bug on their end, and that they can reproduce it. But it's not enough to get the bug fixed. The support may be good if you're asking questions they've heard before - or if you need something like an account lock reset, which the support folks have a button for. But if the problem you…

I’m sure that in the mind of Google they are doing a favor by letting us give them money, wanting support is just ungrateful. Wanting a bug fix is just obscene. They have 150,000 PhDs, aren’t we bold to question them!

This stems from Google not being a service company. Support for products is mostly like this. You can submit a bug report but that does not mean they will help you.

We have a saying here that goes something like "don't buy pizza at a burger joint"... Don't buy services from a advertising / products company.

Re: Ask HN: Gmail account security

#699

Earlier quoted context omitted.

The chance of someone stealing your physical token, and knowing your email + password are almost impossibly low.

But if you lose your 2FA device then you lose access to everything if there is no alternative recovery mechanism. I recently started working with a client that uses cloud-hosted everything and mandates 2FA for all accounts. They asked me to install Google's authenticator app for that purpose. So far, so reasonable. However of those different services, only one provides recovery codes as a standard part of its 2FA reg…

Another scenario where yubikeys shine: you can have multiple. Keep one in your main computer, one on you, and one at your parents's place, or even a safety deposit box if you're feeling fancy.

Re: Ask HN: Gmail account security

#700

As a security professional, this is something we deal with daily. Security is too lax? Why didn't you protect my data. Security is too strong? I can't easily access my data! Can someone show me the Goldilocks zone for internet security? It's a moving target.

Have you considered that these are different groups of people talking?

I'd like to take responsibility for my part by not reusing passwords, not using weak passwords, not using my passwords on computers that I can't trust (other people's PCs, public computers, etc.), etcetra. There's not a whole lot on my end other than physical security and the possibility of malware (not very likely on my systems which generally rely on a small set of linux & bsd packages from distros' official repos). For critical stuff I do some kind of 2fa or OTP too.

Which is to say, it is almost possible for an attacker to gain my credentials.

Now if you do your part, your company won't leak my password either. You won't allow bots to bruteforce trillions of hashes per second. You don't allow your infra or certificates to be compromised. Don't mail me my password. Don't let some rando in if they call or send an email claiming to be me (unless you're a bank and that someone shows up with a valid government issued id plus passes a basic background check). And so on.

If we each do our part, the system is secure. There is no need for you to block access to my account when valid credentials are presented.

The only time I've had a breach that was on me when I was a kid and ran a fucking runescape autominer. Every other time, it's been on the company; either they get breached, or their "security" fails and blocks me. I don't consider that "too strong" security. I consider that weak security, because the job of security is to ensure secure access, and with no access, security has failed its job. And if you permanently lock someone out, as Google has done many times, it's equivalent to putting the user's data through the shredder. That's incredibly bad security; a complete failure to protect the data.

Post reply on HN