8 ms·
Black swan events can happen to you. Recently I traveled to a European country from my base (Middle East). I normally take my phone and laptop with me and they
by yannis 2y ago
Black swan events can happen to you. Recently I traveled to a European country from my base (Middle East). I normally take my phone and laptop with me and they are synced. I forgot the laptop charger and could not get one locally not at least for about a week and then dropped my phone and it got damaged. I bought another phone (Adroid) and tried to log in to by google accounts. It recognized the email and the pswd but then wanted verification from the original device! Despite having the original sim in the new phone.
On my return everything went smoothly through my laptop. Scary though.
My conclusion - have two physical phones + laptop all synced, plus hardcopy of important pswds etc.
Data is easier to protect by offline and online back-ups, but your online identity is hard.
- andersa 2y agoThis is standard Google behavior. Logging into Google on any new device always asks me to confirm it on one of the other devices that are logged in (i.e. phones, tablets). Suppose it's some kind of 2FA.
- yannis 2y agoI understand the security concept of it. Luckily my trip was short. As I also use wechat to communicate with some Chinese friends, my experience was different. First it send me an OTP on the new phone, then asked for two friends to send a number to the phone. Luckily I had the phone number of one and I managed to restore and to be honest having humans in the pipeline was a plus. Negative this had to be done over 5 minutes otherwise you back to square one.
- layer8 2y agoDon't bind your online identity to Apple or Google or Microsoft, in particular not the email addresses you use for accounts. That at least limits the damage they can do.
- CatWChainsaw 2y agoWhich is why they make it so hard to avoid doing this.
- layer8 2y agoUsing your own email account doesn’t generally make things more difficult.
- CatWChainsaw 2y agoI'm thinking of Microsoft Accounts on PCs and how you need to know how to jump through hoops to avoid them at OOBE. And about how this is about AppleIDs and losing them - it's my understanding that Apple is less aggressive about AppleIDs than Microsoft is about Microsoft accounts, but also, TFA. Google has similar levels of fuckery especially if you're on Chromebooks but Google's sin is nonexistent customer support. I wouldn't want my most important email address to be tied to any of these three, although I speak as a gmail-using hypocrite who plans to change that soon.
- toast0 2y agoThe thing that really bugs me about Google is you can make an account tied to an unrelated domain, but then they don't let you use that for a lot of things, so you're forced into a gmail account.
- rchaud 2y agoiTunes didn't even allow you to add your own album art. To do so you had to be signed in with Apple ID, so Apple could look up the album details on the iTunes store and set the image that way. This was in 2008, so the software ecosystem lock-in strategy was already well-established back then.
- lapcat 2y agoThis is utterly false: https://www.youtube.com/watch?v=bnBsIAiZfFc https://www.youtube.com/watch?v=bnBsIAiZfFc You could always edit artwork in iTunes. Indeed, you could import albums from your own CDs and not even use the iTunes Music Store at all.
- rchaud 2y agoThe video you linked is from 2015, almost a decade after the time period I referenced in my comment.
- lapcat 2y ago[flagged]
- generalizations 2y ago> You're seriously doubling down on your ignorance instead of just admitting that you were wrong? From the guidelines: > Be kind. Don't be snarky. Converse curiously; don't cross-examine. Edit out swipes. > When disagreeing, please reply to the argument instead of calling names. "That is idiotic; 1 + 1 is 2, not 3" can be shortened to "1 + 1 is 2, not 3." > Please don't fulminate. Please don't sneer, including at the rest of the community. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- kelnos 2y agoPerhaps something to add to the guidelines: "don't try to weaponize the guidelines when someone calls you out for misrepresenting the facts".
- CydeWeys 2y agoFundamentally it's going to be be bound to someone though. If you run your own domain to host your main email address, you're now bound to the registrar's login to manage that domain name, and also the cloud provider you're using to host the mail services (unless you run that off a machine you have physical access to).
- EasyMark 2y agoIf you use your own domain, open source software, and backup often they can't lock you up forever like Google/Microsoft/Apple tho
- CydeWeys 2y agoYou're missing my point that you're still beholden to the domain name registrar that manages your domain name on your behalf. That account getting permanently locked out will have all the same bad consequences for your online life as your Google account getting locked out. And keep in mind that being a domain name registrar is a low margin business (typically they're only grossing a few bucks per domain per year, before accounting for any other expenses like staffing and systems), so you're not gonna get great support.
- imwillofficial 2y agoI don’t think anyone is arguing that they can get away from the chain of trust required to operate in the modern world. I believe they are advocating for minimizing risk by not deeply integrating with capricious cloud providers.
- Animats 2y agoThe backup for that is a registered trademark on the domain. Recovery via ICANN procedures is slow, though.
- the8472 2y agoMy understandingis is that legally you own the domain and the registrar is only managing it on your behalf and they are required to transfer it to another registrar if they terminate you as a customer. As recently happened for russian users on namecheap for example.
- notyourwork 2y agoThere really isn’t a good solution for this for the masses, is there?
- layer8 2y agoBuying a domain is not difficult, nor is configuring it with a mail service like Fastmail. Yes, it’s slightly more involved than signing up at GMail, but it’s less complicated than doing your taxes (YMMV). The more people do it, the more helpful resources and service would appear for it. The problem is most people don’t care until they get unlucky and their account gets cancelled for inscrutable reasons. It would be better to have regulation that protects users.
- stouset 2y agoThe risk of an average person forgetting to update their credit card details and irrecoverably losing a personal domain is almost certainly thousands of times higher than them being accidentally and permanently locked out of a Google or iCloud account.
- layer8 2y agoWhere I live, the most common payment method for such services is direct debit from your bank account, where the details never change unless you switch banks; and in the rare event that you switch, you can make use of a service that banks are legally required to provide for transferring debit mandates to the new account. I bought my first domain about twenty years ago and never had to change anything regarding payment.
- stouset 2y agoA lot of people live paycheck to paycheck. I’d wager even more people on average would lose their domains with this approach either by forgetting to or being unable to put the necessary funds in their account, and having the payment declined. Losing your entire online identity because you didn’t pay on time is an absolute show stopper for an enormous number of people. Most people are not tech people. They do not know or car, or even care to know, about the details and importance of maintaining and protecting an online identity. They won’t remember to update payment details until things start failing. They won’t check their email frequently enough to notice before this happens. They will ignore text messages, either assuming they’re scams, spam, or unimportant.
- paulmd 2y agoSome failure states are unique to people who exist in these weird edge-case states though. Like the person who had their luggage stolen, the person registered the laptop to their own account, then returned it still paired. And apple wouldn’t un-pair it from Find My even with a police report documenting it all, therefore it’s bricked. (And to be fair to apple here - they didn’t do anything wrong here, strong end-to-end security inherently means allowing these states. Otherwise the cops could order apple to unlock it too, and apple wouldn’t have a moral ground to object if they’re regularly performing the task in other circumstances. Otherwise people could social-engineer apple support to unlock a stolen device, or their partners. To a certain mindset, google and apple not having any real support is a strength because there’s no way to social-engineer your way past the actual security. But people want both the idea of E2E security and the convenience of being able to remotely un-register a laptop from someone else's account...) Anyway, that failure mode wouldn’t exist if they were logged in to their account, and e2e encryption makes that a very low-risk thing overall. Apple can’t see where to it devices are anyway, without doing a song-and-dance to authorize the session on a pre-authed device. Airtags and iphones have a rolling hardware identifier for bluetooth and wifi based on a cryptographically strong pseudorandom sequence, and apple can't correlate the identifiers back to an actual device without a pre-authed device relaying the sequence from your account. Etc etc. Apple have actually done the legwork to make sure they can't see anything (or be forced to reveal anything) if you don't want them to (by enabling E2E), and that actually does drive a lot of "user-unfriendly decisions". And sure, android people will say "that's awfully convenient", but, the end state is still a lot stronger than any other major offering regardless of why you think they're doing it.
- TeMPOraL 2y ago> My conclusion - have two physical phones + laptop all synced, plus hardcopy of important pswds etc. And then say, Meta decides to ask for login verification on your other device, and you lose that account because you always logged to it through a browswer in private mode, so no device actually has an active session. Happened to my wife the other day. IT "Security" is reaching new heights of being bullshit. You can't win, and asking people to buy multiple devices and keep them continuously in sync is a bit much, and not even a guarantee of safety anyway, as next week Google or Amazon will hit you with some next weird trap to keep you "sekhure".
- gruez 2y ago>IT "Security" is reaching new heights of being bullshit. You can't win, and asking people to buy multiple devices and keep them continuously in sync is a bit much You likely don't need to buy multiple devices. I log in from random countries/VPNs all the time and never have issues, but I do have 2fa enabled. If your account only has a password and there was a suspicious sign in attempt, it's reasonable for them to ask for additional verification somehow because you could be a victim of a credential stuffing attack. It's hard for companies to win here. Either people complain about their accounts getting randomly locked because they were on vacation in Romania and tried signing in on a new device, or the companies get grilled by the media for "failing to proactively protect their users' data" or whatever.
- TeMPOraL 2y agoI would agree with you if there actually was anything different in a suspicious way about those logins. There weren't. Same devices, same ISP, same browsers, not even an OS update in between. Just one day, few days ago, out of the blue, Facebook decided to pop up a conformation request, offering no alternative to confirming from "another device", and that's with them knowing (or at least having that information available) that there are no live sessions of that account (the whole browser in private mode thing). Maybe the companies can't win, but they also have themselves to blame. They shouldn't have convinced people to entrust their only copies of data with them. Your vacation photos should not depend on someone's cloud platform. Half of your entire offline life shouldn't depend on Google not randomly locking you out of GMail. But here we are, and I'll keep calling those "security updates" bullshit because they don't care about long tail, and they don't care about hazards they create for most of their users.
- gruez 2y ago> It recognized the email and the pswd but then wanted verification from the original device! Did you have 2fa enabled by any chance? I have 2fa via TOTP on my accounts and while they offer using a signed in phone as a verification option, using TOTP was always an option, and I was never locked out of my account. >Despite having the original sim in the new phone. That would only help if google had some way of tying the installed sim to your account. Given the privacy implications and the technical difficulties, I wouldn't be outraged at the fact it didn't take your sim into consideration.
- yannis 2y agoYes I had 2fa + OTP, however being a new phone they still ask you to tap on the old phone.
- gruez 2y agoAre you talking about a prompt like this[1]? If so, there should be a poorly named "more options" or "don't have your phone?" link that gives you the option to enter your TOTP code instead. [1] https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh0wr6HXhH4GIciHQ4m9_xwDt-Ib1krhZY2_2q8xwR-0R1f10esx3tG7DkbC0KQ4zVFV3zszg3zo5Opta5l1rke2DRnbadLWdjbJyMp8fDuCX3Y3PtRBjYJeVRFURA0RHVKqzPft4j3jYg/s1600/Sign+In.png https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh...
- theragra 2y agoI vaguely remember situation where it was not possible for me to choose such option, but I don't remember details
- SkyPuncher 2y agoThis is actually great. You basically look like a stolen device with a sim swap.
- 05 2y agoHow would the thieves know the password? Even unlocked iPhones don’t show saved passwords without Face ID prompt..
- SkyPuncher 2y agoA reused password that was breached somewhere else.
- fauigerzigerk 2y ago>My conclusion - have two physical phones + laptop all synced, plus hardcopy of important pswds etc. Why do you need more than a single phone plus a hardcopy of your Google recovery codes (assuming you know your Google account password)?
- CatWChainsaw 2y agoIn case one phone doesn't work or is lost or stolen or broken, I guess. Plus buying a second phone is great for the economy! Society was collectively sold this deal where if you entrust everything to a trillion-dollar company, you'll be treated well and this sort of thing wouldn't happen. Yet it appears to be happening, and the trillion-dollar company that has the resources to deal with this so far isn't being very helpful, and it's falling to the consumer to take insane amounts of proactive measures to not have their digital lives fucked up when the exact deal was that you wouldn't have to, but of course now the party line will be "well you were obviously stupid to believe the trillion-dollar company's trillion-dollar marketing, then." And I'm annoyed as one of the people who did not buy into it.
- rchaud 2y agoEven more damaging is the lie that modern tech continues to sell people: that they're too stupid to use computing technology, and all the restrictions of the platform (relative to real computers) are actually for their benefit and not the corporation's.
- CatWChainsaw 2y agoAnd, almost everything is a "computer" nowadays, from your phone to your car to your refrigerator, but only the OG computer is even remotely "fixable" to the average consumer. All the others, you're hamstrung and forced to go through official channels for subpar, marked-up service because if you try to do anything yourself they'll brick your device and maybe sue you for good measure.
- 2y ago
- hedora 2y agoI had a similar experience with google a while back. My conclusion: Eliminate what little remaining usages of their services I have. Doing that with iCloud and Google would be a colossal pain. This event has me thinking more seriously about self-hosting a few more things.
- HenryBemis 2y ago> My conclusion: Eliminate what little remaining usages of their services I have. This. I never used the Apple's Cloud offerings to backup things - and I stopped using any Apple devices since the BatteryGate. I semi-degooglify my Android(s), and never use the "Google-*" (contacts, calendar, etc.). I block them with NoRoot Firewall and disable them, and use other apps for those services. I sync with my Oulook (2013) and my backup is with Carbonite. I do have to jump through a couple of hoops, but considering that I don't live under the threat of 'death' by Apple or Google to hold me hostage with my data/etc, the little effort is well worth it.
- rufus_foreman 2y ago>> I never used the Apple's Cloud offerings to backup things I try not to, but every year I log in and check and there is data stored in their cloud that I specifically tried not to have stored there.
- genevra 2y agoExactly. I recently had the same experience of being locked out when I lost my old device and had no recourse. My conclusion was the same and I've stopped relying on all Google services except Gmail.
- pmarreck 2y ago> when I lost my old device and had no recourse Well, if you used Google 2FA, the Authy app exists, and allows you to securely store 2FA in the cloud (as long as you remember your Authy credentials). If you don't, then yes, your physical phone essentially becomes a dongle and if you lose it, you're screwed. Perhaps they don't educate users enough about this, but that's the fact
- treflop 2y ago1. Use two-factor auth. 2. Save those backup codes. 3. Be able to get those backup codes in some worst case scenario. I have had to start from scratch before but never have been locked out.
- marcosdumay 2y ago4 - Discover that those backup codes are useless because the service provider will refuse to acknowledge them when you travel. The fact that we are stuck with a pair of global apathetic undemocratic identity providers is absurd. And one of the reasons why that "shattered dream of passkeys" is on the front page. At least that dream got shattered, it would be worse if it went through.
- r00fus 2y agoI need to hear more about this scenario.
- BiteCode_dev 2y agoA google account is not required to use an Android device. So if you don't tie all your contacts, sync and backup to your google account, you can have a phone that they won't lock you out of.
- ssl-3 2y agoOr, keep a set of single-use backup codes for 2FA. Google offers this[1], though I don't know if Apple does or not. Storing them seems problematic, but it really isn't: They're just random-looking 8-digit numbers and nobody but you needs to know that they belong to your Google account. Or, KISS. If you're happy with the idea that the SIM card controls the key to the castle, as it seems that you are, then: Put a backup code in a contact in your SIM card. (It is kind of a lost art these days, but SIM cards are still data storage devices here in 2024.) [1]: https://support.google.com/accounts/answer/1187538?hl=en&co=GENIE.Platform%3DAndroid&oco=1 https://support.google.com/accounts/answer/1187538?hl=en&co=...