Live data from Hacker News

Ask HN: Gmail account security

news.ycombinator.com

51–60 of 807 posts

Re: Ask HN: Gmail account security

#51

Oh god, have you had the M.C. Escher-esque experience of trying to sign in to an email account, and it hits you with a two-factor-auth prompt that sent the code to another email address? Imagine the insanity if the email account that received the code in turn asks for a code sent a code to the first one.

Having 2 logins is still 1 factor, the situation is not insanity it's the designed intent of MFA you shouldn't get access in that scenario.

Re: Ask HN: Gmail account security

#52

Oh god, have you had the M.C. Escher-esque experience of trying to sign in to an email account, and it hits you with a two-factor-auth prompt that sent the code to another email address? Imagine the insanity if the email account that received the code in turn asks for a code sent a code to the first one.

Escher or Kafka?

So far as I can tell, 2FA in a low touch environment means it is a matter of when not if you will be locked out without recourse.

Re: Ask HN: Gmail account security

#53
post #7

Wasn't aware of this, but can't say I'm surprised. Personally, I'm still happy with Fastmail, which uses customer subscriptions fees to fund a professional support department, as well as contributing to email-related FOSS. (Among other things, obviously.)

Last week's news gave a lot of people the nudge they needed to finally migrate away from their legacy free GSuite accounts to something more reliable.

Can I ask which news? I'm already a happy Fastmail customer, just curious.

Re: Ask HN: Gmail account security

#54

I once forgot my gmail password. There was no way for me to recover it. Eventually I found it after 6 months, but it was a very difficult 6 months. bank emails, work emails, etc were in the google 7th circle of hell, and there was nothing I could do. I don't have any good advice for you really except is there a way you could vpn to a location closer to where you typically access gmail?

I have one of the old gsuite free accounts with a personal domain, so my backup plan for that for the last ~15 years has always been "if google graveyard gmail, at least I can but mail service elsewhere and update my MX records".

Now they're going to start charging me for that, I'm considering which non-google mail option I will choose instead, I've been sticking with gmail against all my privacy and ethical objections, because it works so well and is free. It's no longer going to be free soon, and I'm pretty sure their competitors work as well as they do (or very close to), so I can _finally_ get over the inertia that's made me feel _almost_ bad enough to leave gmail but not quite bad enough to pay money or do the work required. Right now, it looks like Fastmail or Protonmail are going to get my money.

Re: Ask HN: Gmail account security

#57
post #27

Had this. It was telling me to try again 'later'. Ok, i did 'try later' every day for three weeks, and they didn't let me in. Using the very same IP address as I used to always access it, no less. Then, I gave up, moved all my services to another email account, and after 2 or 3 months tried logging in, and it suddenly allowed me to log in. Needless to say, I will never again use gmail for critically important things.

> Needless to say, I will never again use gmail for critically important things. That's a hot take. If it was critically important, you'd have 2FA and a recovery phone number associated with it - which would have prevented you from getting stuck in a trust-fail situation to begin with. Use whatever service you want, but your takeaway from this situation is a bit absurd. Edit to add: I'm not saying Google's algorithm…

Actually, I specifically declined setting up a recovery phone number because I accessed it from the location where receiving codes would be impossible on my phones. I always accessed it from the same IP using my own VPN server, entered the correct password, and still Google decided that they are 'not sure that it is not really me, try again later'. No thanks.

Re: Ask HN: Gmail account security

#59
post #53

Earlier quoted context omitted.

Last week's news gave a lot of people the nudge they needed to finally migrate away from their legacy free GSuite accounts to something more reliable.

Can I ask which news? I'm already a happy Fastmail customer, just curious.

This [1] Neat fact, Google is yet to tell me they are making this change to my account.

[1] https://arstechnica.com/gadgets/2022/01/google-tells-free-g-...

Re: Ask HN: Gmail account security

#60
post #6

I stopped using gmail. I pay for my own domain (approx $10 per year and subscribe a hosting service that costs about $4/month). The total cost is not much different from a paid google email which is about $50/year. If I happened to forget/lose all passwords (lost laptop, burned house etc.), I would probably need to deal with the hosting company who would try to identify me with my credit card or some other way (phone…

In most cases it’s easy to social engineer hosting company staff into granting unauthorized access (even the major ones) all it takes is a bit of know-how and maybe a photoshopped ID. The weakest link in any security stack is always the human element. The fact that Google makes it impossible to get in touch with a human is why I trust it.
Post reply on HN