3 ms·
> because (like a fool) You are no fool. No doubt you are way above average intelligence. This so-called "security" ecosystem of Big-Tech is a dumpster fire of
by nonrandomstring 4y ago
> because (like a fool)
You are no fool. No doubt you are way above average intelligence.
This so-called "security" ecosystem of Big-Tech is a dumpster fire of
rotting clinical waste. Hope it doesn't spoil your holiday break - and
for goodness sake make a New Year Resolution - to quit this madness
forever.
- makach 4y agoI started working with security to help avoid these kind of scenarios to happen. No doubt gmail is adding controls to their service without fully considering the implications. When security locks you out of your content it is a non-conformity that should be resolved asap zulu.
- stanleydrew 4y agoThis is an unfortunate situation, but calling it a "dumpster fire of rotting clinical waste" is frankly absurd. Google in particular has done more than anyone to acclimate consumers to the usage-patterns of better auth (two-factor in particular). Is everything perfect? Of course not, but things are a lot better than they could be.
- tester457 4y agoI thought it was actually 2 step. The difference always confused me.
- joxel 4y agoNah, this is a complete farce. You’d think by this point google could offer a simple checkbox in the settings of your gmail account: “Do you want this account to be extra secure and for us to lock someone out of it with any activity deemed suspicious?” And then when you don’t click that box they don’t arbitrarily lock your account. But they don’t. Because they’re a dumpster fire company.
- deleted 4y ago[deleted]
- stanleydrew 4y agoI'm not going to try to convince anyone that has their mind made up about "dumpster fire" companies or whatever. For anyone else reading, I'll just say that we all know there are tradeoffs between security and usability and we can actually have a good-faith discussion about that if we want to.
- willhinsa 4y ago"Tradeoffs" that consumers don't get a say in. They don't deserve good faith discussions when they treat us like children and throw away the key when that infantilization destroys stuff in _our_ lives.
- mindslight 4y agoThe problem is that this trade off is between your usability and Google's security, so the choice of their security wins out every time. I have never bought into this regressive corporate security model in which my desktop computer is supposedly less trusted than assorted web app accounts. Unless I've opted in to something different, knowing the password should grant basically full access to the account. If there are additional rules around changing the password or other sensitive meta tasks, then those need to be spelled out in a well defined manner, and not punted to some opaque fickle machine learning scheme based on IP addresses, browser vulnerabilities, phase of the moon, etc.
- shadowgovt 4y agoIt's between your usability and security and the integrity of Google's offering. The lockouts are there because of how easy it is, without them, to compromise someone's email access. People leave their email password lying "in the open" all the time (for a very broad definition of "in the open" that includes things like "re-use it in another site that gets compromised, and use the same username on that site so a cross-site attack attempt is basically a free action for an attacker to take"). When a Gmail account is compromised, people lose everything digital because they've routed their entire digital security story through their Gmail and it's a trivial operation to harvest all that data once an attacker has access. So the damage to an individual is massive when a Gmail account is breached. And since Gmail doesn't actually know who a person is, correction of a breached account is extremely painful (consider, for every method Google might add to prove your identity to restore ownership of your account, how a malicious actor could use that approach to steal your account). I've been on the receiving end of a Gmail lockout (cooked a phone on vacation while my OTPs were stored in an envelope at home), and it sucks. But it sucks less than having my whole digital life story (access to HN, access to every forum I'm on, access to every hosting service I work with, access to every bank account I own) compromised because that Gmail account is the receiving target for every "reset your password" flow of every service I operate with online, and I'm the average use case.