Once upon a time I worked at Google. I returned to Austin to visit old friends and took the opportunity to visit the Google office there. The Googlers sitting around me were primarily corporate sales. They weren't getting any corporate sales calls at all as far as I could tell, but there was one extremely irate user who was locked out of their GMail account and was repeatedly calling them because they were the only h…
It's pretty crazy to think about the fact that your email is de-facto your online identity, as it is the universal second factor that is used as a fallback if other login mechanisms fail. An email service is two things: a global name user@emailprovider.tld, which is really your online identity, and an email service that hosts the SMTP, IMAP and DNS services required for the identity to function. People are willing to…
Ask HN: Gmail account security
741–750 of 807 posts
Re: Ask HN: Gmail account security
#742Arguable email addresses now are more important, that phone numbers. Mobile carriers are legally required to allow you to port numbers. We need a legal framework that allows to have inalienable email addresses.
Or government issued email addresses tied to your identity, either as a citizen or as a registered company. Due to the decentralized nature of email, you can't have inalienable email addresses except within a domain. But you can register your own domain, and then, it is tied to your real identity and you can transfer it between registrars, which may be closer to what you had in mind. Most registrars provide an email…
Re: Ask HN: Gmail account security
#743Earlier quoted context omitted.
You are the product Apple sells to app developers for 30% of their income. Notice that you are not allowed to do things that interfere with this.
That's not at all the same thing as the person I was replying to was claiming, though.
With Apple there is no subtlety because you just can't have what they don't want you to. Apple wants to have a deal with Hollywood so no iOS BitTorrent clients for you. You don't even know that the things you're being deprived of would have been available -- it's the same problem. It's worse. At least with Google if you notice they're removing things you want to see from search results you can switch to another search engine and still use Android. If you want video game ROMs on your iOS device you have to throw it away and buy something else.
And the privacy thing feels like a Trojan horse when they still have all your data on iCloud and have root on your device. Supposedly they don't do anything with it now (except allow iCloud to be subpoenaed by law enforcement without a warrant), and I tend to believe them.
Now suppose we finally get a free hardware phone that isn't a dog. It runs an Android fork with all the privacy invasive stuff stripped out but can still run Android apps and gets OS updates for 10+ years (i.e. indefinitely) because the drivers are in the kernel tree. That would eat a big chunk of Apple's market -- the people who don't want the central control but do want the privacy are going over there. Or just pick whatever scenario you like where Apple's business starts shrinking rather than growing. Nothing lasts forever.
Their executives are under pressure to keep profits up and they have an enormous trove of everyone's data they weren't previously monetizing. Desperate companies do desperate things. Or get acquired by Oracle or AT&T or Huawei.
Since that can happen with non-trivial probability at some future date, you can't put anything on your iPhone you're not willing to have that happen to. And then how is that any better than the alternative? It's even worse if you don't expect it to happen and then it does.
Re: Ask HN: Gmail account security
#744Earlier quoted context omitted.
They do recommend having two keys associated with the account. It’s not cheap, but you can pick up a USB-C small format one and leave it in your computer & get one for your key ring that does NFC / Bluetooth. One is always with you, one is conveniently on your main computer. You can get the least expensive model as a third, off-site backup.
All hardware dies at some point. What if both the Yubikeys die? What if the third one was already dead before and it wasn’t noticed because it wasn’t used recently? This sounds like too deep a maze for I don’t know how much benefit.
All hardware dies, but I also have different keys from different vendors (not just yubico), purchased at different times. The likelihood that all 3 die at the same time is very low. Whether it prevents an attack that would be successful without the physical key (e.g. SIM takeover) is something I won’t ever know. Both of those scenarios are very low likelihood.
But to have this level of security requires extra work, and part of that work is regularly testing that the keys still work. With the increasing account lockouts, this thread is showing me that physical keys may have another advantage.
Most people are set up so that their email account is a “Jesus Nut” [0], so this extra level of security is well worth it as it protects banking, personal files (g drive & photos), password resets / password manager, and purchasing capabilities.
An approach I like is using one’s birthday as a reminder to reset important things - check security keys, check batteries in critical items, test security system, etc.
Re: Ask HN: Gmail account security
#745Earlier quoted context omitted.
In my country (Denmark) every person and legal entity has a government-issued digital identity (NemID) so the authentication process is trivial and cheap.
Did they fix the security flaws mentioned on https://en.wikipedia.org/wiki/NemID yet?
Re: Ask HN: Gmail account security
#746Earlier quoted context omitted.
A plug from a very satisfied customer: I pay $5/month for Fastmail. I've emailed support before and reached a human within hours. They helped me with my problem, because it was their job and I'm paying them to do it. Email is too important to rely on a free service which has a history of shutting people out, at any time, for any reason.
What do you do if Google buys Fastmail?
Re: Ask HN: Gmail account security
#7471) Log in on everything now and then (hm, maybe gotta so that myself soon); and perhaps even more important,
2) When getting a new device / phone number / email address, log in to everything from the new one before getting rid of the old one. That way, you can jump back to the old and confirm the validity of the new. Then set up the new phone number for 2FA / email as your backup address / recognised login device... Only then can you dispose of the old.
Re: Ask HN: Gmail account security
#748Earlier quoted context omitted.
I understand you are saying this in good faith, but honestly this is bullshit. Is the only way to get a solution to use LinkedIn inmail to solve a login crisis? There are plenty of FB engineers on this site alone. Are you all feeling okay with the work you’ve done?
There’s plenty of ways: 1) Get your story on HN front page 2) Get a job at FB, fix issue yourself 3) Install Tinder, drive near FB offices, set search radius to minimum. Try to convince your matches to fix things 4) Buy a 0-day from the dark web, hack into FB and reset the password 5) Become incredibly wealthy, acrue enough FB stock to get a board seat, complain to the CEO
3 b) Install Grind[e?]r, drive near FB offices, set search radius to minimum. Try to blackmail your matches to fix things
(Yeah, it's a good thing that's a lot less blackmail-worthy nowadays. About as serious as what I'm replying to.)
Re: Ask HN: Gmail account security
#749Earlier quoted context omitted.
Did they fix the security flaws mentioned on https://en.wikipedia.org/wiki/NemID yet?
The provider of the system is being replaced, which means that NemID will be replaced with MitID. This solves some security issues, but brings others. Most importantly, MitID, unlike NemID, does not allow the service provider to embed the login form, but always sends you to the identity provider to log in. On the other hand, you no longer need to input both a password and use a second factor (key card, code generator…
Re: Ask HN: Gmail account security
#750Earlier quoted context omitted.
It plays out with Amazon absolutely crushing Google when it tried to be a consumer marketplace, and even trouncing Google at providing web infrastructure services. If, somehow, an antitrust ruling split ads from the rest of Google the non-ads remainder wouldn't last more than a few years.
Alphabet as a whole is an organization built by the immense money that comes from monopolizing digital advertising (through some very... unscrupulous means) and then run by people deluding themselves into thinking they can do anything else. There's a reason everything is "killed by google" - I'm not exactly sure anyone there knows how to do damn near anything that isn't propped up by investor hype and the money they…
https://www.theverge.com/2021/7/27/22596592/google-q2-2021-r...
I think it's projected to earn 20 billion this year.