Live data from Hacker News

Ask HN: Gmail account security

news.ycombinator.com

731–740 of 807 posts

Re: Ask HN: Gmail account security

#731

Earlier quoted context omitted.

What about downloaded back up codes ? Phone push approval? U2f key? Authenticator app? Can't imagine complaining about being shut out if you didn't have at least one or all of these set up. Google even nags you about setting these up.

Why can't you imagine that? This gatekeeping you're doing is rude and doesn't make sense. 2FA's very purpose is to increase shut outs when enabled.

It might be 2FA's very purpose, but I've found that a 2FA-less account is a lot more distrusting of logins. Some of my relatives don't have 2FA set up and they got more "verify it's really you" prompts compared to my personal MFA'd account.

Re: Ask HN: Gmail account security

#732

Earlier quoted context omitted.

Why can't you imagine that? This gatekeeping you're doing is rude and doesn't make sense. 2FA's very purpose is to increase shut outs when enabled.

It might be 2FA's very purpose, but I've found that a 2FA-less account is a lot more distrusting of logins. Some of my relatives don't have 2FA set up and they got more "verify it's really you" prompts compared to my personal MFA'd account.

Because Google is abusing the concept.

Re: Ask HN: Gmail account security

#733

Earlier quoted context omitted.

Maybe they don't want you to file the bug too easily? I imagine Google would getting 10,000s bugs per day if it was too easy.

I'd rather know where my ship is burning instead of closing my eyes and just having happy thoughts. But then, I am an engineer, not some marketing drone...

Curious but how would you figure out where the ship is burning if you are receiving a larger number of bug reports, e.g. 1 million bug reports per month?

Loads of duplication will also follow etc. Sounds like you need entire teams to figure out what the real bugs are at that point and maintain the bug list? Though I can't think of a workflow from the top of my head.

Re: Ask HN: Gmail account security

#734

Earlier quoted context omitted.

Its craziness all the way down. I have a google voice number which is my "default" number with my gmail accounts. All my gmail accounts were automatically migrated to use 2FA with this number which means if I lose all my google devices and I try to log into voice, I'll get 2FA I can't see because of the catch-22 situation of not being able to log into voice. The only reason I caught this is because they send me a not…

> Voice SMS is a mess too. 50% of services can't SMS it a code because Google blocks it. Other services won't accept it for SMS codes because its "not a real phone." The first part of that shouldn't be true. I've used mine to receive all kinds of SMS and it always works fine _except_ for the services that just won't accept the number. Only run across maybe one or two of those, over some years. For SMS from real peopl…

Discord won't take the numbers, Venmo won't take the numbers.

Re: Ask HN: Gmail account security

#736
post #42
post #32

Earlier quoted context omitted.

Even with a FIDO2/U2F/WebAuthn key? If so, yeah that's pretty bad..

Yeah I got locked out dispite having printed codes and authy setup. Lasted a day or so

That's a scary thought, being locked out of a primary email address despite taking security seriously.

I currently have it secured with my backup codes (printed and stored in a secure location), as well as two Yubikey (one primary, one backup).

I'd be seriously angry if Google locked me out of my account.

Re: Ask HN: Gmail account security

#737
post #718

Earlier quoted context omitted.

I worked at both Amazon and Google. It was only at Amazon where I was exposed to the Craft of software development. Personally, I feel there is a nuanced difference to the role at Amazon being SDE ( Software Development Engineer ) whereas Google is SWE ( Software Engineer ). It's almost like Google thinks Software Developers are lower tier than Software Engineers, but I'd like to think of myself as doing more than ju…

It's a bit ironic that you're bashing Google and praising Go in the same paragraph, never mentioning that Go is designed and supported by Google.

I think that was part of the point. Google made Go and then when OP wanted to use Go, their bosses said “use Java” (and took a month to do something that could be done in a few days)

Re: Ask HN: Gmail account security

#738

Earlier quoted context omitted.

(edited) If you don't mind sharing, what is the bug? - My comment originally read as follows, 2 people downvoted it. >I work at Google and recently tried to file a bug about the calculator embedded in search. It was dastardly difficult to find how to file the ticket. It took me maybe an hour. A better system for filing tickets internally and for filing and triaging tickets from external users would be a tremendous as…

You just found a bug in Google Calculator. You wrote "calories" but Google is giving you the answer in "kilocalories". If you change "calories" to "kilocalories" the answer doesn't change. I wonder how many times in the past has it given you the wrong answer without you noticing?

[deleted]

Re: Ask HN: Gmail account security

#739
post #411

Earlier quoted context omitted.

Fastmail's UI is just faster too.

IME, that's my biggest complaint. Even plain text emails take 2+ seconds to load.

Somethings wrong or suboptimal for you. Just tested this in the middle of the US with some messages from years ago to make sure they weren't cached and it was like 2-3 tenths of a second.
Post reply on HN