At least Google doesn't recycle usernames unlike other services and account retention is trivially automatic if you use an Android phone.
Ask HN: Gmail account security
541–550 of 807 posts
Re: Ask HN: Gmail account security
#542Nearly every interaction I have had with Google in the last two years makes me think the company has devolved into warring factions that cannot communicate let alone coordinate for the betterment of their users. Do they not eat their own cooking, or how do they manage to make everything so dysfunctional?
Maybe they should come up with a new chat app that will fix the communication issues.
Re: Ask HN: Gmail account security
#543Earlier quoted context omitted.
> obviously if someone can authenticate with a YubiKey they are practically guaranteed to be the real person. Or someone grabbed your backpack. I understand why Google wants 2FA - it gives them a stronger claim to not provide support. Personally I don't want 2FA - I use strong passwords, and I don't trust them to provide support if my device is lost. Imagine a house fire, for instance, and losing not only your posses…
The chance of someone stealing your physical token, and knowing your email + password are almost impossibly low.
I recently started working with a client that uses cloud-hosted everything and mandates 2FA for all accounts. They asked me to install Google's authenticator app for that purpose. So far, so reasonable.
However of those different services, only one provides recovery codes as a standard part of its 2FA registration process. For everything else, if my work phone gets stolen or broken, that's it, game over for those accounts. I would need to contact the administrator for each service on my client's team and get them to restore access somehow.
Re: Ask HN: Gmail account security
#544Earlier quoted context omitted.
There’s plenty of ways: 1) Get your story on HN front page 2) Get a job at FB, fix issue yourself 3) Install Tinder, drive near FB offices, set search radius to minimum. Try to convince your matches to fix things 4) Buy a 0-day from the dark web, hack into FB and reset the password 5) Become incredibly wealthy, acrue enough FB stock to get a board seat, complain to the CEO
Someone should sell VPN exit nodes next to BigTech offices so that people can exit their Tinder there and do the (3) connection approach without the drive.
Re: Ask HN: Gmail account security
#545What piss me off the most with Gmail and google things like meet, is that if you are on Android, there is no way to login in a single app: Gmail, meet or even a third party email app without associating your Google account to the whole phone. This is really annoying. Sometimes I have to join corporate meeting from my personal email account on my personal phone, because if I would like to login with my pro one, all my…
Re: Ask HN: Gmail account security
#546Re: Ask HN: Gmail account security
#547Earlier quoted context omitted.
With Google’s nonexistent customer service I’d be afraid of being locked out for any arbitrary reason and having no recourse no matter what recovery procedures I prepared for. Contrast that to my bank where I can go to the branch, show ID, and get problems logging in resolved.
A plug from a very satisfied customer: I pay $5/month for Fastmail. I've emailed support before and reached a human within hours. They helped me with my problem, because it was their job and I'm paying them to do it. Email is too important to rely on a free service which has a history of shutting people out, at any time, for any reason.
Re: Ask HN: Gmail account security
#548Earlier quoted context omitted.
A plug from a very satisfied customer: I pay $5/month for Fastmail. I've emailed support before and reached a human within hours. They helped me with my problem, because it was their job and I'm paying them to do it. Email is too important to rely on a free service which has a history of shutting people out, at any time, for any reason.
Still the problem with Fastmail is the same as with Google. Leaning on 3rd party service that you have no control of. There are so many things that could go wrong there, they can be hacked, go bankrupt, closed by authorities, insided. Everyone should have an appropriate personal disaster recovery plan that includes stuff like recovering from loss of service supplier.
Re: Ask HN: Gmail account security
#549Re: Ask HN: Gmail account security
#550Earlier quoted context omitted.
Even so, we still need to have a debate about what levels of "papieren bitte" we are willing to accept for different functions of society. The currently ubiquitous corporate-centric trend is to "nudge" instead of outright ban, i.e. instead of a bool it's numeric, and I highly doubt that the difference in data type is as significant as people think it is -- "Well you can always create a new account/buy another device/…
"Papiere, bitte." (Just fyi. Mangling the German [sic] doesn't detract from your post.) Not sure being corporate centric makes this problem any worse? If you had other kinds of organisation, you'd still have to deal with abuse and fraud? Any people doing weird, unusual stuff, look inherently more suspicious. That's a fact of life in meatspace, too. There might be some utopian, ideal way to organise activity so that n…
Thanks!
> Not sure being corporate centric makes this problem any worse? If you had other kinds of organisation, you'd still have to deal with abuse and fraud?
I think it's definitely not unique to big corps, but an emergent property of a distributed and homogenous system of self interested agents, probably. It feels very game theoretical, at least. What's clear is these systems are becoming ubiquitous rapidly.
Anyway, if my Google account gets locked today, for whatever reason, I am very seriously screwed. Google's human appeal process is best-effort at best, I know people personally who have been locked out for life. Now, I have the luxury to blame myself because I should have bought a domain and so on, but society at large doesn't have that foresight/insight.