Live data from Hacker News

Ask HN: Gmail account security

news.ycombinator.com

91–100 of 807 posts

Re: Ask HN: Gmail account security

#91
Yep, and it was even more aggravating.

> have three gmail accounts

> primary, name.surname@gmail.com

> secondary, name.surname.purchases@gmail.com

> tertiary, name.surname.work@gmail.com

> secondary and tertiary have primary as a recovery address

> log in/out once a week in 2nd and 3rd

> last August, try to log into name.surname.work

> "Password is incorrect"

> WTH?! of course it's correct.

> try several times, Google blocks me ("temporarily")

> next day, try again, no dice.

> OK, the hell with this: let's reset the password

> "what's the last password you remember?" duh, the last and only password is the one I already gave you, you stupid machine.

> "we need additional verification; input the recovery address" Finally! type my main address

> mail from Google arrives pronto, code in it

> type code in verification field

> new mail from Google: "Thank you for verifying your mail address" [my primary one?!] Based on the information provided, we cannot ascertain that [tertiary account] belongs to you"

This has been happening since. A few weeks ago, secondary account went down too, yielding the same error OP got.

Note: a) I have been using the same IP and the same machine to log into those accounts for many years; there is no other device or location where I've signed in before! b) primary account has multiple (4) Yubikeys associated with it, so it should be clear I'm a real person and not a bot.

I'm currently in panic mode: if my main account goes down, it will take a huge part of my life with it, from banks to government stuff.

Re: Ask HN: Gmail account security

#92
post #26

Once again this shows that we're at the mercy of the giant AI machine. For fear of having my data locked into Google, I migrated to my own domain and e-mail hosting elsewhere. I'm still at the mercy of the hosting and domain registrar at that point, but at least they have phone numbers I can call to get support and talk to a human. Offline backups is a must at this point.

> at least they have phone numbers I can call to get support and talk to a human.

This is important. I've decided to move all of the services I care about to a paid platform with properly paid support staff. This whole 'get it for free!' crap with the tech companies is just too much risk. I make more than enough money, I can afford a few bucks for the things that matter. Gmail is an awful choice for something so critical as your primary email account.

Re: Ask HN: Gmail account security

#94
post #68

Earlier quoted context omitted.

With Google’s nonexistent customer service I’d be afraid of being locked out for any arbitrary reason and having no recourse no matter what recovery procedures I prepared for. Contrast that to my bank where I can go to the branch, show ID, and get problems logging in resolved.

I personally had a great experience with google support when I once stupidly locked myself out of my account. The whole thing was resolved in about 3 days. However, google customer service is definitely erratic since loads of other people have had bad experiences. The best thing to do if you're using Gmail is to enable 2fa and backup the recovery codes offline and somewhere safe. This could probably get you into your…

I have never heard of anyone anywhere ever being able to access Google support once they were locked out -- you need to be logged in to access what little tech support they offer.

Re: Ask HN: Gmail account security

#95

This is because most people use Gmail for basically all their online accounts: if you don't directly login to the site via Gmail, you can use your account to change your password. Imagine the damage which can be done if a malicious user breaks into someone's Gmail, if not your own, then the average person who uses the same password everywhere and trusts Gmail with everything. Not defending the practice at all. It sho…

this only works if your post gets upvoted.

which in the grand scheme of things is rare. have you been to the "new" page lately?

Re: Ask HN: Gmail account security

#96
post #16

That doesn't help OP now, but I found it helpful to enable 2FA with Google Authenticator, and keep emergency backup codes in a safe place. It's slightly more hassle, but there are less 'soft AI' barriers between you and your successful login. I'd also suggest not to rely on a phone number as 2nd factor, it's not that super safe.

> 2FA with Google Authenticator I just wanted to recommend Aegis as an alternative to Google Authenticator. It allows backing up codes to an encrypted (password protected) file. Plus it's FOSS.

I use 1password as an Authenticator replacement, which saves time when logging in.

Re: Ask HN: Gmail account security

#97
Just FYI there is a solution to this: enroll your gmail account in the advanced protection program

https://landing.google.com/advancedprotection/

When you login you are required to use a security key (like Yubi key) but it removes all the annoying emails and texts with codes, IP filtering, login AI, etc

Re: Ask HN: Gmail account security

#98
post #27

Earlier quoted context omitted.

> Needless to say, I will never again use gmail for critically important things. That's a hot take. If it was critically important, you'd have 2FA and a recovery phone number associated with it - which would have prevented you from getting stuck in a trust-fail situation to begin with. Use whatever service you want, but your takeaway from this situation is a bit absurd. Edit to add: I'm not saying Google's algorithm…

With Google’s nonexistent customer service I’d be afraid of being locked out for any arbitrary reason and having no recourse no matter what recovery procedures I prepared for. Contrast that to my bank where I can go to the branch, show ID, and get problems logging in resolved.

"With Google’s nonexistent customer service"

Quite. If you play the game then all is well but if you don't then you are given very short shrift and no recourse to a higher power or anything at all.

There is very little oversight. If you fall afoul of the "algorithm" or whatever bollocks is running the show, then you have to fall back on calling them out on the socials. Get enough traction on that and lo: "soz, lol, we failed here but your is important to us ... in this case ... etc ..."

Re: Ask HN: Gmail account security

#99
there needs to be some kind of law or regulation around this right? email has become as, if not more important as regular mail, and the government should be protecting access to it.

try sending it to your senator and local representative. I think the FTC would also be interested in this. if google won’t even give you support for the issue, that should really be addressed by the government imo.

Re: Ask HN: Gmail account security

#100

Earlier quoted context omitted.

I’d recommend a non-Google 2FA app. Microsoft has one, and Authy is popular. Personally I’m happy with OTP Auth. Some password managers can also handle 2FA, e.g. Strongbox.

Any particular reason?

1. In a thread about being locked out of google services because of AI black box, it makes sense to reduce dependence anywhere possible

2. If you get a new device, you need to un-enrol and re-enrol in all 2fa providers with g authenticator - it's a nightmare. Very hard if the old device got fatally dropped in a pool! I know at least with Authy you can carry the tokens to a new device.

Post reply on HN