Live data from Hacker News

Ask HN: Gmail account security

news.ycombinator.com

201–210 of 807 posts

Re: Ask HN: Gmail account security

#201

One day I logged in to my Amazon account from a different country. Mind you, I have 2FA/OTP enabled in my account, and I entered it correctly. They also made me click on a link they sent via email to "verify my login". A couple hours later my account was blocked due to "suspicious login(s)" (i.e. mine), and the order I placed cancelled. They had me wait 24h until I could contact someone at support that could unblock…

[deleted]

Re: Ask HN: Gmail account security

#202

Earlier quoted context omitted.

With Google’s nonexistent customer service I’d be afraid of being locked out for any arbitrary reason and having no recourse no matter what recovery procedures I prepared for. Contrast that to my bank where I can go to the branch, show ID, and get problems logging in resolved.

FYI, google has customer service if you're paying them. I pay $6 a month for gsuite. I've contacted customer service 3 times. Got them instantly.

I've read stories here on HN about non-existent Google customer support from people who worked at companies that were paying Google millions.

Re: Ask HN: Gmail account security

#203

Earlier quoted context omitted.

Or maybe do they really want your phone number? (Uninformed guess but isn't it valuable data?)

My phone number is probably the least valuable thing Amazon knows about me, I figure.

Phone numbers are basically super cookie identifiers unless you make a new phone number for each account and use different aliases & maybe addresses for them too. They all sell into centralized information systems and create profiles about you that are very detailed, which includes banking, income and credit info. So yes, the phone number is incredibly valuable, especially a place like amazon that shows different prices to different users and who's recommendation engine drives a lot of sales.

Phone 2 factor is pretty much the only kind of 2 factor most people will accept, and for most people the phone number probably has better security than most people's emails, because most people reuse passwords, while with phones you had to do a special non-password effort for them.

Re: Ask HN: Gmail account security

#204

Had this. It was telling me to try again 'later'. Ok, i did 'try later' every day for three weeks, and they didn't let me in. Using the very same IP address as I used to always access it, no less. Then, I gave up, moved all my services to another email account, and after 2 or 3 months tried logging in, and it suddenly allowed me to log in. Needless to say, I will never again use gmail for critically important things.

My solution is, buy your own domain. It's cheap and it will cost you only 20$ a year or something like that. I'm not saying run your own email service (I do, but I recognize that it's complex and not worth for most people), but use a public email service (like also GMail) with your own domain. That way at least if you no longer can access your account, or you get banned, or whatever, you don't loose your address (sin…

[deleted]

Re: Ask HN: Gmail account security

#205

Earlier quoted context omitted.

With Google’s nonexistent customer service I’d be afraid of being locked out for any arbitrary reason and having no recourse no matter what recovery procedures I prepared for. Contrast that to my bank where I can go to the branch, show ID, and get problems logging in resolved.

A plug from a very satisfied customer: I pay $5/month for Fastmail. I've emailed support before and reached a human within hours. They helped me with my problem, because it was their job and I'm paying them to do it. Email is too important to rely on a free service which has a history of shutting people out, at any time, for any reason.

Reasonably confident one of my support tickets even got answered by the CEO once. They're a shockingly human-focused company.

Re: Ask HN: Gmail account security

#206
post #96

Earlier quoted context omitted.

> 2FA with Google Authenticator I just wanted to recommend Aegis as an alternative to Google Authenticator. It allows backing up codes to an encrypted (password protected) file. Plus it's FOSS.

I use 1password as an Authenticator replacement, which saves time when logging in.

Bitwarden ($10/year Premium Bitwarden plan[1] or self-hosted Vaultwarden[2]) and KeePass[3] are also password managers that support TOTP authentication. They are open source and less expensive than 1Password.

A single password manager should only be used to store TOTP secrets alongside passwords if you're comfortable with both of them being accessed from the same devices. It's possible to store your TOTP secrets in a Bitwarden account or a KeePass file, and your passwords in another account or file, hosted/stored in different locations.

[1] https://bitwarden.com/pricing/business/

[2] https://github.com/dani-garcia/vaultwarden

[3] https://keepass.info/download.html

Re: Ask HN: Gmail account security

#207

Earlier quoted context omitted.

With Google’s nonexistent customer service I’d be afraid of being locked out for any arbitrary reason and having no recourse no matter what recovery procedures I prepared for. Contrast that to my bank where I can go to the branch, show ID, and get problems logging in resolved.

A plug from a very satisfied customer: I pay $5/month for Fastmail. I've emailed support before and reached a human within hours. They helped me with my problem, because it was their job and I'm paying them to do it. Email is too important to rely on a free service which has a history of shutting people out, at any time, for any reason.

Yep, Fastmail is great. Google cannot be trusted. With google you are the product, not the customer. The Fastmail service and features are better than gmail as well.

Re: Ask HN: Gmail account security

#208

Earlier quoted context omitted.

this only works if your post gets upvoted. which in the grand scheme of things is rare. have you been to the "new" page lately?

(you're all checking out the 'new' page now, aren't you?)

I browse 'new' most of the time, because there is a lot of interesting stuff that never makes it to the front page.
Post reply on HN