Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm sorry for the trouble you're having. I have on idea of what's happened and why but thought it timely to point out for the benefit of those reading this thread:

I highly suggest you use two-factor authentication with GMail:

http://googleblog.blogspot.com/2011/02/advanced-sign-in-secu...

Or Jeff Atwood's post on this:

http://www.codinghorror.com/blog/2012/04/make-your-email-hac...

Your email is too valuable to be left open to attack, hijacking or theft.



cough If any Googlers are reading this, Google often phrases error messages more like that quote ("Us us us us us us, ergo, you don't get what you need") instead of like cletus did ("You you you, you you you, ergo, we're going to take this action on your behalf".). Dale Carnegie, Cletus, and every sane copywriter on the planet strongly suggest rewriting that prompt and related ones.

After taking baby steps like sounding like one cares more major interventions like actually caring may be called for. (I enormously respect the Googlers who I know that that line will discomfit but this is criticism that you guys have gone out of your way for years to earn.)


My wife has had two-factor authentication for at least a year, she only accesses gmail from her iPod touch and the browser on her laptop, and she had this happen to her about a month ago. No recourse. It came back eventually, but apparently two-factor auth is not sufficient to prevent this issue.


I am, of course, already using 2FA, but I completely agree that everyone should have it set up.


If this is true, why is cletus bringing it up?


I think that the root of this issue is the stupid Google policy of not distinguishing any variation of your address if a '.' character is in there -- until someone registers it. People get confused and try to login.

So if your address is jsmith@gmail.com, you can send email to (or login with) j.smith@gmail.com or jsmit.h@gmail.com.... at least until someone registers jsmit.h@gmail.com!

I was an early beta GMail user have a reasonably common first initial last name GMail address. I probably get 3-5 password reset attempts per month. I also routinely received a variety of interesting misdirected emails. Everything from someone's VPN credentials, a US military EEOC complaint, invitations to a stag party in Ireland, a video of a paratransit bus flipping over (intended to be sent to an investigator), to girls modelling underwear for boyfriends.


False. It is not possible to register multiple variants of the same address. The reason you get misdirected email is because people are entering the wrong address in forms. You should see all the email that goes to paul@gmail.com :)


Out of curiosity, is it enough to make the account unusable? Do you have to set up strong filters?


On an (un)related note, my google voice phone number is (xxx)-234-5678, and it is completely unusable. You should hear the kind of voice mails that I get. I have started archiving the most amusing ones in my account. I have been blocking the numbers from area code (xxx) since I registered that number (June/2009), but it is still not usable.


Do share. That sounds like a blog post waiting to happen.


With Gmail, j.s.m.i.t.h@gmail.com is the same address as jsmith@gmail.com as j.smith+nospam@gmail.com - it's likely that someone's mistyping their own email address all over the Internet (this happens to me all the time, having a common first name/last name combo. I get bills and newsletters and etc. Never got an underwear pic, though, alas!).

Good thing to remember this when writing a system that compares email addresses--always normalize Gmail addresses on the backend before processing--but woe betide you if you normalize on the frontend, people love their dots!


> So if your address is jsmith@gmail.com, you can send email to (or login with) j.smith@gmail.com or jsmit.h@gmail.com.... at least until someone registers jsmit.h@gmail.com!

Uh, if this is true it's a security abomination. I'm pretty sure Gmail doesn't allow registration with a login that would be considered the same as an already registered one (but I'm too lazy to check a few to confirm, just because I refuse to believe Google could be that dumb).


I just tried logging in with a random '.' in my username and got in.


That doesn't actually contradict what the guy I responded to said though; you'd want to try signing up for gmail with a few variations of your own login that have a few random extra '.'s. My assumption is that these would all be rejected due to the fact that the canonicalized version (all lowercase and with all periods removed) matches the canonicalized version of a currently registered login, but this guy was saying that's not the case.

But anyway, paul responded so it's a moot point.


You can also send a email to a gmail address with dots in it so sending a email to john.smith@gmail.com can be received by johnsmith@gmail.com, john.smi.th@gmail.com, etc. and vice versa.


Really, that works (surprise, not incredulity)? I have a period in my gmail address, but have never tried that. Seems like a very strange default.


Google's got enough of my info.

If they want to come up with a two-factor auth, I'm happy to provide the public half of a PKI keypair. Of my choosing.

Not my phone number, thanks.

My real email is too valuable to be left to GMail.


You can get a list of 1-time pads instead.


To setup 2 factor auth, you have to give them a phone number that you can receive a call or sms on, I believe.


I'm pretty sure that's just for recovery. The actual setup involves scanning a QR code in the Authenticator app, which is the seed for the TOTP - http://en.wikipedia.org/wiki/Time-based_One-time_Password_Al...


Yes, but they show you that QR code only AFTER you gave them your phone number and typed in the confirmation code.


Which is why I provide my Google Voice number for this purpose. Works perfectly!


I know it is not a perfect solution but there is an Authenticator app that you can use on Android. I believe that iOS might have one too but I am not sure.

This solution does not require you to give them your phone number :).


And for all things not Google, check out http://www.duosecurity.com/. Completely painless to set up on my box at home.


Wow, I've wanted such a thing for a while, but hadn't gotten around to researching. Thanks for this!


Really? It is now a suggested policy to use additional authorization flows in order to use this email service?

Are we talking about the same email service? You know, the one that's supposed to be so awesome that you'll quickly forget about getting your email the "old fashioned way" by having to mess with those pesky things like setting up a POP/IMAP account on your host provider?

Talk about things coming full circle.

[Addendum} No, haven't had my email hacked. I guess I was a little blow-hardy, thanks for responses :)


gmail is a large high-visibility target.

I, for one, appreciate the fact that 2FA is available with the service. Everyone should have it turned on for any high-value mail account they own, Google or no-Google.


Take a look at, for example, "Abuse at Scale" from the Gmail folks at April's RIPE conference for an idea of the threat.

https://ripe64.ripe.net/presentations/48-AbuseAtScale.pdf

1 million+ bogus authentication attempts per day, 60-100k auths per second (legit and not), etc.


That's definitely an eyeopener. Gracias.


Well, ideally, 2factor should be used for anything with sensitive information... Frankly, I wish I could have enabled 2factor waaaaay earlier on GMail.


I take it you've never had your email account hacked, then?


And hope your phone isn't stolen, losing access to your email? That's why I've always avoided two factor authentication -- it's scary enough losing your phone, but then you're locked out of your email as well?

(Perhaps coloring my perception is that I have a pay-as-you-go phone currently.)


I'd love to do this, but my Apps account gives me no such opportunity to setup 2FA, following those instructions: http://cl.ly/242v451j3g331U393u34


Apps account administrator should enable 2FA for the domain. I have this option in all of my Apps administrator panel.


Ahh, thanks!


Their is no excuse for not using two-factor authentication with all Google products.


Not that it's a very strong excuse, but it -can- be fairly annoying if the prompt appears and your phone is dead (or not nearby, or lost).


That's why as part of setting up 2F they suggest you generate and print a list of backup verification codes. 2F wouldn't even be an option if they didn't provide an emergency out.


Or hey, get a real host, domain, and E-mail account.

In other news: Someone else's blog is under my Blogger account, and there's absolutely no way to contact Google about it.

The new credo of doing business is HIDE FROM THE CUSTOMER. It's disgraceful.


If you're not paying them you're not the customer.


As several have pointed out: You are paying.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: