Live data from Hacker News

Google hacked account

news.ycombinator.com

71–80 of 169 posts

Re: Google hacked account

#71
post #58

Earlier quoted context omitted.

My mistake was that I didn't enable 2 factor authentication. Kind of aggressive calling out Google's engineers when you couldn't bother protecting yourself with their free and easy to use security mechanisms.

Except that now Google has my phone number linked to my identity too. I know this is not everyone's use case, but for those of us that care deeply about privacy, that's not a good alternative. If that's not a good counterpoint, my phone/SMS service sucks when I'm traveling abroad, which is exactly when Google thinks I'm not me. I wish Google supported TOTP like Github does, without asking for a phone number.

> I wish Google supported TOTP like Github does... Goid nees, they do! They even have an app for it.

https://en.m.wikipedia.org/wiki/Google_Authenticator

Re: Google hacked account

#72

You had two step verification, or not? I'm hoping you'll say no, because my feeling of security comes from the fact I've enabled TSV.

What kind of two factor authentication? TOTP codes don't protect you against e.g. phishing. A MITM can request codes and forward them (since they are time-based).

Get a U2F key. They work with Google accounts and provide much better protection against phishing (the phishing site does not have the key handle and cannot initiate the challenge-response as a result):

https://www.yubico.com/products/yubikey-hardware/fido-u2f-se...

Re: Google hacked account

#73

> What to do? The first step would be to edit the title of your submission to begin with "Ask HN: hacked Google account, what to do?", since you're asking a question. "Google hacked account" means, to an English speaker, that Google perpetrated hacking against some account somewhere (subject-verb-object, right?) E.g. Google people gained access to your bank account. I.e. your current submission title is clickbait.

That's the least relevant thing you can tell someone with 130+ points and 60+ comments.

Re: Google hacked account

#74

You had two step verification, or not? I'm hoping you'll say no, because my feeling of security comes from the fact I've enabled TSV.

What kind of two factor authentication? TOTP codes don't protect you against e.g. phishing. A MITM can request codes and forward them (since they are time-based). Get a U2F key. They work with Google accounts and provide much better protection against phishing (the phishing site does not have the key handle and cannot initiate the challenge-response as a result): https://www.yubico.com/products/yubikey-hardware/fido-…

I love my Yubikey! I use it with all my Google accounts.

Re: Google hacked account

#75

Earlier quoted context omitted.

Remember: We're not Google's clients, we're Google's products

Please stop repeating this intellectually lazy and false meme. Or go to reddit; platitudes that don't require critical thinking tend to do better there.

And fat people! Reddit is full of fatties!

Re: Google hacked account

#76

The issue is that you're not Google's client. Maybe buy something from them (a large amount of ads), then try to get support?

Remember: We're not Google's clients, we're Google's products

Not necessarily. If you use Google Apps, you pay a monthly fee and are a client, with telephone support, no ads, etc.

Re: Google hacked account

#77
post #34

> So far not a problem, but the email you get back after sending the password reset request contains a link to a page that allows you to cancel the request (not sure the genius who had this idea) Did you set the recovery email the same as the main email? Cause I only get password reset to the recovery email. If you used the same address for recovery email, then it defeats the whole purpose

no i set another email. but still both emails will get the link.

[deleted]

Re: Google hacked account

#78

You had two step verification, or not? I'm hoping you'll say no, because my feeling of security comes from the fact I've enabled TSV.

"You had two step verification, or not?"

Upvoted you but...

A company offers a free service. "Your aunt" does know know or understand the need for "two step verification" nor do almost certainly a large percentage of people using gmail.

This idea that companies resolve themselves of all responsibility to provide reasonable customer support for a free product with such wide adoption is ridiculous. Google derives benefit from the relationship regardless of the fact that the service is free.

Re: Google hacked account

#79
I guess you just need to be faster than the person who hacked your account. Just before the cancel link is clicked you gotta make your move.

Yeah, and the cancel request was a total stroke of genius!

Re: Google hacked account

#80
post #45
post #33

Earlier quoted context omitted.

Genuinely asking: is there a paid email provider roughly on par with Google's offerings in terms of usability and uptime? I'd consider switching.

If you need all the features of Gmail or Inbox, probably not. If you can get by with what IMAP has to offer, FastMail has been very solid for me. I pay about $50 a year for a single account, which can support lots (unlimited?) domains and addresses (both sending and receiving). The web UI is nice, and the iOS app is pretty good, too. They also blog a lot about what they are doing on the technical side, and seem reall…

They are excellent! I had a feature request twice, it was implemented on their beta server within days. Their (standard-conforming) IMAP and Webmail is really fast (they cache recent stuff on SSDs). They have apps now for Android and iOS (basically wrappers around the web app with notification support, but they work well enough). They recently added CalDAV and CardDAV support.

On top of all of that, they actively contribute to open source projects such as Cyrus.

Post reply on HN