Live data from Hacker News

Ask HN: Gmail account security

news.ycombinator.com

61–70 of 807 posts

Re: Ask HN: Gmail account security

#61
I have solved this couple of months ago:

1) dont try to login couple of weeks (this was recommended on multiple boards)

2) try again with the recovery email

My problem was a) I didn't log in during the previous 12 months b) I moved to another country.

Only when I connected via vpn to the country of my previous residence, I got in. Took me more then 4 months to figure this out...

Re: Ask HN: Gmail account security

#62
post #50
post #16

That doesn't help OP now, but I found it helpful to enable 2FA with Google Authenticator, and keep emergency backup codes in a safe place. It's slightly more hassle, but there are less 'soft AI' barriers between you and your successful login. I'd also suggest not to rely on a phone number as 2nd factor, it's not that super safe.

Would be good but on my accounts which didn't have 2FA, they seemed to have removed Authenticator as an option: only phone numbers available now.

You still can if you muck around with the dark-UX flow.

Re: Ask HN: Gmail account security

#63
post #7

Wasn't aware of this, but can't say I'm surprised. Personally, I'm still happy with Fastmail, which uses customer subscriptions fees to fund a professional support department, as well as contributing to email-related FOSS. (Among other things, obviously.)

Fastmail's UI is just faster too.

It's too bad their app doesn't have offline support. I use that feature of Gmail app a lot

Re: Ask HN: Gmail account security

#65
post #16

That doesn't help OP now, but I found it helpful to enable 2FA with Google Authenticator, and keep emergency backup codes in a safe place. It's slightly more hassle, but there are less 'soft AI' barriers between you and your successful login. I'd also suggest not to rely on a phone number as 2nd factor, it's not that super safe.

Easily the most straightforward recommendation possible. Thank you.

HN outrage at Kafkaesque account lock-outs makes me imagine bureaucrats complaining about an approval requirement they themselves created. It is frustrating and I know data loss can be devastating. If people in the tech community individually follow basic security procedures, that helps us further discover pain points in the work toward better security. Who better to have to deal with these problems than people who focus on leveraging effort?

Re: Ask HN: Gmail account security

#66
post #7

Wasn't aware of this, but can't say I'm surprised. Personally, I'm still happy with Fastmail, which uses customer subscriptions fees to fund a professional support department, as well as contributing to email-related FOSS. (Among other things, obviously.)

I'm still a happy Fastmail customer after around 17 years.

Re: Ask HN: Gmail account security

#67
They also do this thing now where they block [1] smaller browsers (even ones using the latest version of chromium) under the guise of security. According to their docs they're fighting MITMs by generally disallowing any browser they can't identify (so the big few).

If you're not on a whitelisted browser by Google, you can't log in (effectively, use) any of their properties.

This feels very anti-competitive to me. Notably all the whitelisted browsers are either theirs (Chrome) or sell them their search traffic. I'm building a browser for research [2] and have to frequently find workarounds. I'm not quite sure who I'd contact to get on said whitelist either...

[1] https://imgur.com/a/DASVkhl (here is the issue in the Vim browser and Min browser)

[2] https://synth.app

Re: Ask HN: Gmail account security

#68
post #27

Earlier quoted context omitted.

> Needless to say, I will never again use gmail for critically important things. That's a hot take. If it was critically important, you'd have 2FA and a recovery phone number associated with it - which would have prevented you from getting stuck in a trust-fail situation to begin with. Use whatever service you want, but your takeaway from this situation is a bit absurd. Edit to add: I'm not saying Google's algorithm…

With Google’s nonexistent customer service I’d be afraid of being locked out for any arbitrary reason and having no recourse no matter what recovery procedures I prepared for. Contrast that to my bank where I can go to the branch, show ID, and get problems logging in resolved.

I personally had a great experience with google support when I once stupidly locked myself out of my account. The whole thing was resolved in about 3 days.

However, google customer service is definitely erratic since loads of other people have had bad experiences. The best thing to do if you're using Gmail is to enable 2fa and backup the recovery codes offline and somewhere safe. This could probably get you into your account without needing to talk to support.

Re: Ask HN: Gmail account security

#69
post #16

That doesn't help OP now, but I found it helpful to enable 2FA with Google Authenticator, and keep emergency backup codes in a safe place. It's slightly more hassle, but there are less 'soft AI' barriers between you and your successful login. I'd also suggest not to rely on a phone number as 2nd factor, it's not that super safe.

> 2FA with Google Authenticator

I just wanted to recommend Aegis as an alternative to Google Authenticator. It allows backing up codes to an encrypted (password protected) file. Plus it's FOSS.

Re: Ask HN: Gmail account security

#70
post #7

Wasn't aware of this, but can't say I'm surprised. Personally, I'm still happy with Fastmail, which uses customer subscriptions fees to fund a professional support department, as well as contributing to email-related FOSS. (Among other things, obviously.)

Last week's news gave a lot of people the nudge they needed to finally migrate away from their legacy free GSuite accounts to something more reliable.

Yep. I've been a Fastmail customer for a while with a couple of my own personal accounts, but our family e-mail domain was a legacy GSuite account. I'd get pushback from my brothers when I'd suggest we switched to a paid service, because they didn't want to pony up for email accounts for their kids. Cheapskates :). But now Google is forcing the issue, and Fastmail is cheaper. And they have a $3/month account which is good for the kids who don't get tons of email.
Post reply on HN