Live data from Hacker News

Google hacked account

news.ycombinator.com

61–70 of 169 posts

Re: Google hacked account

#61
post #45
post #33

Earlier quoted context omitted.

Genuinely asking: is there a paid email provider roughly on par with Google's offerings in terms of usability and uptime? I'd consider switching.

If you need all the features of Gmail or Inbox, probably not. If you can get by with what IMAP has to offer, FastMail has been very solid for me. I pay about $50 a year for a single account, which can support lots (unlimited?) domains and addresses (both sending and receiving). The web UI is nice, and the iOS app is pretty good, too. They also blog a lot about what they are doing on the technical side, and seem reall…

Second this too! I've been with Fastmail since 2011 and their service is excellent.

Re: Google hacked account

#62
post #39

Earlier quoted context omitted.

Please stop repeating this intellectually lazy and false meme. Or go to reddit; platitudes that don't require critical thinking tend to do better there.

Your best bet at stopping a false meme is to replace it with a better one. What do you recommend?

I would go with

> You're not Google's product, you're their supplier; one of their many millions of suppliers.

Their product is your personal information, which you supply to them in exchange for their services. The fact that you are one of many millions of suppliers (each dealing in microtransactions) means you don't have a lot of weight when you need to get help from them.

Re: Google hacked account

#63
If they're going to have cancel password change requests they also have to have cancel change of alternative email requests. That's the first thing a hacker changes.

Additionally, you have to track every change with a timestamp so that you can invalid everything that came AFTER the change you just reset. That will prevent a hacker from being able to screw with the account because the original email address will also be able to cancel future changes, no matter how many times the perpetrator did it.

Re: Google hacked account

#64
post #17

I guess is all about: how can you prove you're not the hacker?

Location of past IPs used to access GMail

Knowledge about items on the inbox/address book

Location of devices used to access the account

Knowledge of past passwords

Not sending password reset emails to secondary emails that have just been added

Re: Google hacked account

#66
post #58

Earlier quoted context omitted.

My mistake was that I didn't enable 2 factor authentication. I contacted them and offered to supply a copy of my password and driver license, they said the only way is to go through the dysfunctional online method to recover the password. I did create another account, they still send the link to cancel the request to the original account!!!

My mistake was that I didn't enable 2 factor authentication. Kind of aggressive calling out Google's engineers when you couldn't bother protecting yourself with their free and easy to use security mechanisms.

Except that now Google has my phone number linked to my identity too. I know this is not everyone's use case, but for those of us that care deeply about privacy, that's not a good alternative.

If that's not a good counterpoint, my phone/SMS service sucks when I'm traveling abroad, which is exactly when Google thinks I'm not me.

I wish Google supported TOTP like Github does, without asking for a phone number.

Re: Google hacked account

#67
post #40
post #33

Earlier quoted context omitted.

Genuinely asking: is there a paid email provider roughly on par with Google's offerings in terms of usability and uptime? I'd consider switching.

I know HN frowns on "me too" responses but I am in the same boat. I'm heavily dependent on GMail right now and each time I see a story about someone having troubles on Google's non-charging (I hesitate to say "free") services I make a mental note to find a paid alternative, but never follow up.

To me-too your "me too", I switched to FastMail three years ago and haven't looked back.

Re: Google hacked account

#68
post #39

Earlier quoted context omitted.

Your best bet at stopping a false meme is to replace it with a better one. What do you recommend?

I would go with > You're not Google's product, you're their supplier; one of their many millions of suppliers. Their product is your personal information, which you supply to them in exchange for their services. The fact that you are one of many millions of suppliers (each dealing in microtransactions) means you don't have a lot of weight when you need to get help from them.

Catchy ;-)

The best counter to the lazy Google meme is to think of all the companies where you are indisputably the customer and you also get awful incompetent support.

Re: Google hacked account

#69
post #58

Earlier quoted context omitted.

My mistake was that I didn't enable 2 factor authentication. Kind of aggressive calling out Google's engineers when you couldn't bother protecting yourself with their free and easy to use security mechanisms.

Except that now Google has my phone number linked to my identity too. I know this is not everyone's use case, but for those of us that care deeply about privacy, that's not a good alternative. If that's not a good counterpoint, my phone/SMS service sucks when I'm traveling abroad, which is exactly when Google thinks I'm not me. I wish Google supported TOTP like Github does, without asking for a phone number.

Does gmail support using a second email as the second factor? Hotmail does...
Post reply on HN