Had this. It was telling me to try again 'later'. Ok, i did 'try later' every day for three weeks, and they didn't let me in. Using the very same IP address as I used to always access it, no less. Then, I gave up, moved all my services to another email account, and after 2 or 3 months tried logging in, and it suddenly allowed me to log in. Needless to say, I will never again use gmail for critically important things.
My solution is, buy your own domain. It's cheap and it will cost you only 20$ a year or something like that. I'm not saying run your own email service (I do, but I recognize that it's complex and not worth for most people), but use a public email service (like also GMail) with your own domain. That way at least if you no longer can access your account, or you get banned, or whatever, you don't loose your address (sin…
Ask HN: Gmail account security
441–450 of 807 posts
Re: Ask HN: Gmail account security
#442Earlier quoted context omitted.
> it is definitely doing non-trivial fingerprinting Can confirm. To generalize and understand why, big corps have to deal with an insane amount of (often automated) abuse, so they build profiles using data collection to assess your risk level. Being in the wrong cohort (say unusual browser, small country, rare language, use a vpn etc) can affect your score. Basically it's these massive bayesian filters that output ho…
To clarify, these scores can be sanely used to decide what level of trust you have, and when you have none you get a capcha, a SMS check or something heavier to authorize the access you are trying to get. In my book you’re never supposed to fully block a session because of the score, there needs to be a (potentially burdensome) way to prove the score wrong. Blocking a browser should be out of question.
Unfortunately google doesn't have the support infrastructure like a bank to do recoveries.
Re: Ask HN: Gmail account security
#443Earlier quoted context omitted.
1. In a thread about being locked out of google services because of AI black box, it makes sense to reduce dependence anywhere possible 2. If you get a new device, you need to un-enrol and re-enrol in all 2fa providers with g authenticator - it's a nightmare. Very hard if the old device got fatally dropped in a pool! I know at least with Authy you can carry the tokens to a new device.
I just want to chip in and say that 2. can be helped somewhat by having a second device (maybe old smartphone on wifi) that you export all authenticator keys to. Stick the old phone in a safe and make sure it's still working every so often (2x/year?) This is relatively new - a few years ago Authenticator did not support this. Oh, and make sure before you use the emergency device, time is synced - codes won't work oth…
Thanks, this was around when my device went for a swim.
Re: Ask HN: Gmail account security
#444Earlier quoted context omitted.
Wow, that's awful. I wonder who's idea it was? Is it doing anything more than checking user agent (trivial to spoof), because if not that seems entirely hostile.
Likely the goal is to protect users from malicious apps, trying to get user to log in on a hosted browser component in order to scrape their data (or perform activities on behalf of user).
People are having their lives ruined when their account gets breached which Google prioritizes over avoiding accidentally blocking a few odd users.
Re: Ask HN: Gmail account security
#445I returned to Austin to visit old friends and took the opportunity to visit the Google office there. The Googlers sitting around me were primarily corporate sales.
They weren't getting any corporate sales calls at all as far as I could tell, but there was one extremely irate user who was locked out of their GMail account and was repeatedly calling them because they were the only human beings at Google the user was able to get in touch with, via something like "Press 3 for Corporate Sales." Of course these poor Google corporate sales people had absolutely no way to help this user even if they wanted to. Google literally did not have any GMail account phone support (at least at the time).
I could hear the poor guy screaming through their headsets about how he paid Google something for some service and was entitled to phone support and he demanded someone help him, but they just kept saying, "This is corporate sales. We do not offer consumer account support. If you want support, please visit the Google Support Forums at www dot..."
After they hung up on him 3 or 4 times, eventually a manager got on the phone and told him (between his screams), "Look, you're not getting any phone support because it doesn't exist. There's nowhere for us to transfer you. There's nobody who can call you back about this. Your only option is to search the forums for an answer to your problem. I am going to terminate this call now. Sir, I'm going to terminate this call. No, we can't help you. Nobody at Google can help you. I am terminating this call now. We asked you to stop calling this number. Do not call us again. "
I'd frequently tell my co-workers, "If you're not paying for it, you're the product." That experience underscored that notion for me.
Re: Ask HN: Gmail account security
#446Earlier quoted context omitted.
I did this! Kind of. I bought a domain and was lucky enough to get in to a custom domain email (and more) service with a big company years ago when they had a free version. Unfortunately... it was Google (so kind of hiring the wolf to care for my sheep, as it turns out). And now they're cutting off all of us free tier folks. Which I can't fault them for, but still blame them for. Because I'm petty and entitled or wha…
Same situation here. Have you done the research yet to decide on a new service, or are you planning on starting to pay? For me ideally I would like to move to something else (even paid) just because someday Google deciding to block me for whatever reason scares me quite a bit after having everything for the last decade attached to this account. I would like to export my emails, switch my domain to the new service, an…
Re: Ask HN: Gmail account security
#447Yep, and it was even more aggravating. > have three gmail accounts > primary, name.surname@gmail.com > secondary, name.surname.purchases@gmail.com > tertiary, name.surname.work@gmail.com > secondary and tertiary have primary as a recovery address > log in/out once a week in 2nd and 3rd > last August, try to log into name.surname.work > "Password is incorrect" > WTH?! of course it's correct. > try several times, Googl…
Perhaps you're not supposed to have more than 1 gmail account, and the assumptions in their code cannot deal with more than 1 account per user, or worse, they actively try to discourage it.
Re: Ask HN: Gmail account security
#448Re: Ask HN: Gmail account security
#449Maybe 10 years ago I experienced forgotten Gmail password hell when a family member forgot their password and was never able to recover the account.
Can't wait to see what the process is like another 10 years from now.
Re: Ask HN: Gmail account security
#450Just FYI there is a solution to this: enroll your gmail account in the advanced protection program https://landing.google.com/advancedprotection/ When you login you are required to use a security key (like Yubi key) but it removes all the annoying emails and texts with codes, IP filtering, login AI, etc