Live data from Hacker News

Ask HN: Gmail account security

news.ycombinator.com

271–280 of 807 posts

Re: Ask HN: Gmail account security

#271

Had this. It was telling me to try again 'later'. Ok, i did 'try later' every day for three weeks, and they didn't let me in. Using the very same IP address as I used to always access it, no less. Then, I gave up, moved all my services to another email account, and after 2 or 3 months tried logging in, and it suddenly allowed me to log in. Needless to say, I will never again use gmail for critically important things.

My solution is, buy your own domain. It's cheap and it will cost you only 20$ a year or something like that. I'm not saying run your own email service (I do, but I recognize that it's complex and not worth for most people), but use a public email service (like also GMail) with your own domain. That way at least if you no longer can access your account, or you get banned, or whatever, you don't loose your address (sin…

https://purelymail.com/ is cheap and great, albeit still in beta.

Re: Ask HN: Gmail account security

#272

Earlier quoted context omitted.

With Google’s nonexistent customer service I’d be afraid of being locked out for any arbitrary reason and having no recourse no matter what recovery procedures I prepared for. Contrast that to my bank where I can go to the branch, show ID, and get problems logging in resolved.

A plug from a very satisfied customer: I pay $5/month for Fastmail. I've emailed support before and reached a human within hours. They helped me with my problem, because it was their job and I'm paying them to do it. Email is too important to rely on a free service which has a history of shutting people out, at any time, for any reason.

I prepay for the 3-year package and it comes out to $3/mo or something. I'm not going to stop using email, and Fastmail is fantastic so I'm not going to switch away, so it's worth prepaying.

Re: Ask HN: Gmail account security

#273

Earlier quoted context omitted.

With Google’s nonexistent customer service I’d be afraid of being locked out for any arbitrary reason and having no recourse no matter what recovery procedures I prepared for. Contrast that to my bank where I can go to the branch, show ID, and get problems logging in resolved.

A plug from a very satisfied customer: I pay $5/month for Fastmail. I've emailed support before and reached a human within hours. They helped me with my problem, because it was their job and I'm paying them to do it. Email is too important to rely on a free service which has a history of shutting people out, at any time, for any reason.

What do you do if Google buys Fastmail?

Re: Ask HN: Gmail account security

#274

Earlier quoted context omitted.

Quoted post unavailable.

I don't know if it's FUD, but it's true. It happened to a person I know, and in her case, the resolution was "ask around until a friend of a friend of a friend of a friend works at Google". She literally had to ask her friend, who asked me, I asked one of my friends to ask one of his friends who works at Google to put in an internal ticket. It was thankfully resolved quickly (she lost access to all her work materials…

> It was thankfully resolved quickly (she lost access to all her work materials),

More than your own domain, BACKUPS.

Re: Ask HN: Gmail account security

#275

Had this. It was telling me to try again 'later'. Ok, i did 'try later' every day for three weeks, and they didn't let me in. Using the very same IP address as I used to always access it, no less. Then, I gave up, moved all my services to another email account, and after 2 or 3 months tried logging in, and it suddenly allowed me to log in. Needless to say, I will never again use gmail for critically important things.

Not just Google, I'm regularly locked out of banks, state resources, and all kinds of other shit because of various combinations of bad decisions producing toxic login flows.

One of my personal favorites -- a bank automatically associated phone numbers you called them from to the account, and later they forced SMS 2FA onto the account regardless of any other security you had in place (and of course made the common mistake of allowing account takeovers with JUST that 2FA and a username). Those automatically registered numbers weren't exempted.

Re: Ask HN: Gmail account security

#276
I dont recall the password of my old gmail account and I listed my current gmail account as the recovery email, and they still cannot recover the account for me. It makes absolutely zero sense. It just seems like entirely lazy.

Re: Ask HN: Gmail account security

#277
post #192

Earlier quoted context omitted.

I agree. I change my phone number often and this is annoying. It's also very annoying that most EU banks rely on SMS codes to confirm transactions as it's quite easy to clone SIM cards. Yet they don't support real OATH OTP. I hate Office 365, but I have to concede that their login is much more robust. I use passwords + OATH and it's truly reliable. Gmail has locked me out very often for no clear reason. Besides they…

Not my experience in the germanic portions of Europe. Every bank i’ve been involved with in the last 20 years has had otps of one kind or another.

That's interesting. What 2FA system do they use exactly?

AFAIK, N26 still uses on-time codes sent by SMS which I regard as very insecure.

Re: Ask HN: Gmail account security

#278
I had this in ~2014 at an event. It literally would not let me log in no matter what.

This did reinforce that running my own email server was a good idea. Like, what are you going to do if it actually is important? Call google support? I'd be surprised if they have a helpdesk with humans nowadays, let alone to fix some free account at 1am in the morning. Or even if you get to talk to a human, what are they going to do? Disable a security measure because a kind voice asks them to?

Google thought my IP address was in Russia (I was in Germany) and I guess that makes it suspicious? (Feels a bit odd that entire countries are basically banned. Not as if criminals can't use a VPS or VPN, it's security theater and seems insulting to everyone living there: they're all considered guilty until proven innocent.) I think I later checked and saw that there were no other active login sessions, so it knew that I could not possibly have done as it suggested. (Or maybe that was another instance of this problem, not sure anymore after 5+ years. I never forgot the lesson though...) The reason for logging in wasn't time-sensitive so I let it go for the four days of the event.

A related problem is that I have to clean up my inbox after logging into various services. Twitter was one of the first and I apparently got annoyed enough that I stopped using it subconsciously (I only later noticed that I had stopped checking Twitter and figured that the annoyance factor must be the reason). Like yeah you don't recognize my device, I don't want your "tweet" buttons across the web to track me so of course this appears as a new login device. What would be more suspicious is a login from a known device to this account, if the machine learning functions correctly...

Re: Ask HN: Gmail account security

#279

Earlier quoted context omitted.

Quoted post unavailable.

I don't know if it's FUD, but it's true. It happened to a person I know, and in her case, the resolution was "ask around until a friend of a friend of a friend of a friend works at Google". She literally had to ask her friend, who asked me, I asked one of my friends to ask one of his friends who works at Google to put in an internal ticket. It was thankfully resolved quickly (she lost access to all her work materials…

Indeed, I only consider myself tangentially in the tech world, but I do have access to a private facebook group with many old co-workers and sometimes this sort of request will go out to current FB or Googlers. Inevitably some will complain that it's inappropriate and should go through official channels and others will point out that this back channel is often the only real resolution.

Re: Ask HN: Gmail account security

#280

One day I logged in to my Amazon account from a different country. Mind you, I have 2FA/OTP enabled in my account, and I entered it correctly. They also made me click on a link they sent via email to "verify my login". A couple hours later my account was blocked due to "suspicious login(s)" (i.e. mine), and the order I placed cancelled. They had me wait 24h until I could contact someone at support that could unblock…

The amount of trust that providers put in phone numbers is absolutely insane.

Yeah I have a pool of virtual numbers and use them for any of this bull, and rotate them in/out. No business needs to know my phone number.
Post reply on HN