Live data from Hacker News

Google hacked account

news.ycombinator.com

111–120 of 169 posts

Re: Google hacked account

#111
post #78

You had two step verification, or not? I'm hoping you'll say no, because my feeling of security comes from the fact I've enabled TSV.

"You had two step verification, or not?" Upvoted you but... A company offers a free service. "Your aunt" does know know or understand the need for "two step verification" nor do almost certainly a large percentage of people using gmail. This idea that companies resolve themselves of all responsibility to provide reasonable customer support for a free product with such wide adoption is ridiculous. Google derives benef…

Yea but technical strong people like yourself are always able to handle themselves better in all aspects of computing.

This is why you end up fixing your aunts printer. And why you have a more secure e-mail account than her. And why you can handle backing up your photos.... etc

It's not Google's fault entirely.

Re: Google hacked account

#113
If they are automatically clicking these links you may be able to spoof an E-mail that looks similar to the password reset request but have the cancel link actually log them out.

Going to this URL logs you out on Gmail: https://accounts.google.com/Logout?service=mail&continue=htt...

This might not work, but it's probably worth a try.

Re: Google hacked account

#114

You had two step verification, or not? I'm hoping you'll say no, because my feeling of security comes from the fact I've enabled TSV.

What kind of two factor authentication? TOTP codes don't protect you against e.g. phishing. A MITM can request codes and forward them (since they are time-based). Get a U2F key. They work with Google accounts and provide much better protection against phishing (the phishing site does not have the key handle and cannot initiate the challenge-response as a result): https://www.yubico.com/products/yubikey-hardware/fido-…

> What kind of two factor authentication? TOTP codes don't protect you against e.g. phishing.

Sure it does. TOTP codes are only good for X seconds and most phishing scammers merely collect the information to use much later (I have seen the source behind the actual phishing sites).

I have yet to hear of a story of someone's account being compromised while using TOTP (knock on wood).

But seriously though - companies like Google, Facebook, Gandi, Dropbox, and Microsoft all use TOTP. So I would wager that TOTP is pretty safe to use.

Re: Google hacked account

#116
post #71

Earlier quoted context omitted.

Except that now Google has my phone number linked to my identity too. I know this is not everyone's use case, but for those of us that care deeply about privacy, that's not a good alternative. If that's not a good counterpoint, my phone/SMS service sucks when I'm traveling abroad, which is exactly when Google thinks I'm not me. I wish Google supported TOTP like Github does, without asking for a phone number.

> I wish Google supported TOTP like Github does... Goid nees, they do! They even have an app for it. https://en.m.wikipedia.org/wiki/Google_Authenticator

And a PAM module!

Re: Google hacked account

#117
post #78

Earlier quoted context omitted.

"You had two step verification, or not?" Upvoted you but... A company offers a free service. "Your aunt" does know know or understand the need for "two step verification" nor do almost certainly a large percentage of people using gmail. This idea that companies resolve themselves of all responsibility to provide reasonable customer support for a free product with such wide adoption is ridiculous. Google derives benef…

Yea but technical strong people like yourself are always able to handle themselves better in all aspects of computing. This is why you end up fixing your aunts printer. And why you have a more secure e-mail account than her. And why you can handle backing up your photos.... etc It's not Google's fault entirely.

"but technical strong people like yourself"

I like the sound of that. I actually have run my own mail servers since the mid 90's [1] but I am more of a business guy who knows computers than a strong technical guy the way that I see it. I don't use gmail (for anything important I do use it for unimportant things) I don't like the idea of my mail sitting on their servers.

[1] Actually if you include non internet mail dates back to the mid 80's on a Unix system V.

Re: Google hacked account

#118
post #40
post #33

Earlier quoted context omitted.

Genuinely asking: is there a paid email provider roughly on par with Google's offerings in terms of usability and uptime? I'd consider switching.

I know HN frowns on "me too" responses but I am in the same boat. I'm heavily dependent on GMail right now and each time I see a story about someone having troubles on Google's non-charging (I hesitate to say "free") services I make a mental note to find a paid alternative, but never follow up.

I have my work e-mail on Zoho, but I haven't been able to free myself from Gmail... the inertia is too great (plus the integration to all the other Google services).

I do have two-factor authentication after a scare.

Re: Google hacked account

#119
Google provides some great services, but support is lacking.

I suggest, for the future: 1) use two factor authorization 2) use a separate email service because email is so important that you need the best support, etc. that you can get (I use Fastmail) 3) periodically download your Google data so if you ever need to set up a new Google account, you have some of your old context

I do still use GMail, but as a backup email.

I am going to start teaching free Internet security and privacy classes at my local library so I have been thinking a lot about these issues. Google, Facebook, Twitter, etc. provide really nice services, but it is important to consider privacy issues and have a plan for using these "free" services.

Re: Google hacked account

#120
I would see if you can upgrade your gmail to a paid account and then contact their support. Free accounts get very little attention but paid accounts will get you to a real person eventually.
Post reply on HN