Live data from Hacker News

Ask HN: Gmail account security

news.ycombinator.com

561–570 of 807 posts

Re: Ask HN: Gmail account security

#561

Earlier quoted context omitted.

Google sometimes blocks me from searching using Firefox, saying it’s “suspicious activity” and sending me into captcha hell that always rejects my results after several screens for no reason. It’s incredibly transparent as to what they’re doing. That Google became the most anti-consumer company out there is pretty disgraceful.

Hanlon's razor applies here, though.

No it doesn't, rockefeller's razor applies - don't attribute to stupidity what could be adequately explained by profit motive.

Re: Ask HN: Gmail account security

#562

Earlier quoted context omitted.

The beauty of AI is that it's likely no human can say precisely why two similar users might get a different classification.

...and the beauty of the Internet is that there's really no way to be sure people are being genuine...

Long time Firefox user and HNer here.

I've at least been "captchaed" in Firefox. While being logged in with my Gmail account from 2005.

Re: Ask HN: Gmail account security

#563
post #470

Earlier quoted context omitted.

You are actually pointing out a tremendous opportunity that Google has internally and externally. I work at Google and recently tried to file a bug about the calculator embedded in search. It was dastardly difficult to find how to file the ticket. It took me maybe an hour. A better system for filing tickets internally and for filing and triaging tickets from external users would be a tremendous asset for Google.

I guess this is why Amazon is playing the long game with their obsessive focus on customers. I don't know how that really plays out where the rubber meets the road but that's what Jeff bezos always keeps talking about.

Really?

I am locked out of my (10+ years old) account for almost two years, due to "security reasons" (I have valid OTP so I call this BS and my credit card has changed in between so the account is useless for anyone), they want me to call some number in states, but I am not giving my phone number away, which is also the reason why I don't create new account.

I have calculations, in last two years I have bought 4378 EUR online. This could be collected by Amazon - but now it isn't.

I am still waiting when they will come to their senses and figure out that locking out users (especially if they made quite a few purchases) longer than few months is counterproductive.

Meanwhile they are losing money they could earn. Good job.

Re: Ask HN: Gmail account security

#564
post #67

They also do this thing now where they block [1] smaller browsers (even ones using the latest version of chromium) under the guise of security. According to their docs they're fighting MITMs by generally disallowing any browser they can't identify (so the big few). If you're not on a whitelisted browser by Google, you can't log in (effectively, use) any of their properties. This feels very anti-competitive to me. Not…

Interesting how the brand of security companies like Google keep telling us is in our best interests always seems to secure their corporate revenue streams first, while the security and freedom of users are an afterthought.

years ago I interviewed with a startup that was aiming to put their routers in various locations like airports and coffee shops. They would offer free or cheap internet at those locations. The catch: they were going to swap out ads with their own ads on the fly.

Shortly after that, Google started pushing HTTPS. I never believed that was a coincidence.

Re: Ask HN: Gmail account security

#565

Once upon a time I worked at Google. I returned to Austin to visit old friends and took the opportunity to visit the Google office there. The Googlers sitting around me were primarily corporate sales. They weren't getting any corporate sales calls at all as far as I could tell, but there was one extremely irate user who was locked out of their GMail account and was repeatedly calling them because they were the only h…

>about how he paid Google something for some service

>I'd frequently tell my co-workers, "If you're not paying for it, you're the product."

it seems even if he did pay he was the product, which frankly jibes with my experience of paying for things at Google.

Re: Ask HN: Gmail account security

#566

Once upon a time I worked at Google. I returned to Austin to visit old friends and took the opportunity to visit the Google office there. The Googlers sitting around me were primarily corporate sales. They weren't getting any corporate sales calls at all as far as I could tell, but there was one extremely irate user who was locked out of their GMail account and was repeatedly calling them because they were the only h…

only tangentially related but that phrase is a pet peeve of mine. You are always the product if you are using software - free or paid. Netflix is sure as hell going to use your data the same way youtube would. The only exception of course is most but not all FOSS.

Is that true for Apple?

Re: Ask HN: Gmail account security

#567

Once upon a time I worked at Google. I returned to Austin to visit old friends and took the opportunity to visit the Google office there. The Googlers sitting around me were primarily corporate sales. They weren't getting any corporate sales calls at all as far as I could tell, but there was one extremely irate user who was locked out of their GMail account and was repeatedly calling them because they were the only h…

I've subscribed to Google One for a few years. (When I say "pay", I'm using credit from answering surveys from Google a few times a week). It's only a couple of dollars a month, it gives you more online cloud storage, but it also gives you a chat and call service to Google. I have used it a couple of times - once to help me push LG to release updates on a phone (they kept saying it was Google's responsibility), anoth…

[deleted]

Re: Ask HN: Gmail account security

#568
Just yesterday, I got two 'Google' verification codes to my mobile number out of the blue. No number, so I've only got 'Google' as the sender to go on.

  * My password is very long and complicated and stored in a password manager
  * I don't use any device I don't own and can see the moment the SMS messages came
  * I have no other indication that I've been compromised
I'm thinking it's more likely that someone else added my phone number as a second factor to their account.

Google: Just one damn easy thing would give me more information about the situation and allow me to act appropriately: Have the email address associated with the verification code in the message.

Re: Ask HN: Gmail account security

#569
post #257

Earlier quoted context omitted.

It's not just the user-agent, it is definitely doing non-trivial fingerprinting (both linked projects also had UA mitigations before). We don't have an easy workaround (besides a sketchy cookie hack that took hours to reverse engineer) right now and have been trying to get in touch with them.

> it is definitely doing non-trivial fingerprinting Can confirm. To generalize and understand why, big corps have to deal with an insane amount of (often automated) abuse, so they build profiles using data collection to assess your risk level. Being in the wrong cohort (say unusual browser, small country, rare language, use a vpn etc) can affect your score. Basically it's these massive bayesian filters that output ho…

> Obviously this is well established in the insurance and finance industries, but make no mistake, it happens everywhere.

Speaking from someone in the US--in both insurance and finance I can get a person on the phone to resolve my issue.

Specific to finance, there are a number of consumer laws that protect me.

If I'm denied credit based on my credit history, I'm allowed to know why. If my credit score is not accurate, I'm allowed the ability to fix it.

Lousy customer support is not a tech industry issue--Stripe, Amazon, Apple, to name three all have great support.

Re: Ask HN: Gmail account security

#570
post #257

Earlier quoted context omitted.

> it is definitely doing non-trivial fingerprinting Can confirm. To generalize and understand why, big corps have to deal with an insane amount of (often automated) abuse, so they build profiles using data collection to assess your risk level. Being in the wrong cohort (say unusual browser, small country, rare language, use a vpn etc) can affect your score. Basically it's these massive bayesian filters that output ho…

To clarify, these scores can be sanely used to decide what level of trust you have, and when you have none you get a capcha, a SMS check or something heavier to authorize the access you are trying to get. In my book you’re never supposed to fully block a session because of the score, there needs to be a (potentially burdensome) way to prove the score wrong. Blocking a browser should be out of question.

I know cloudflare uses a trick with canvas element to fingerprint the browser. If you disable it, it can be actually impossible to bypass.

It's not so much a social credit score to fear rather than privacy. Any site using cloudflare or Google knows where you're going and what your doing and if they don't then, access denied.

They know so much more than your innocent mind will want to admit.

Post reply on HN