Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Really? It is now a suggested policy to use additional authorization flows in order to use this email service?

Are we talking about the same email service? You know, the one that's supposed to be so awesome that you'll quickly forget about getting your email the "old fashioned way" by having to mess with those pesky things like setting up a POP/IMAP account on your host provider?

Talk about things coming full circle.

[Addendum} No, haven't had my email hacked. I guess I was a little blow-hardy, thanks for responses :)



gmail is a large high-visibility target.

I, for one, appreciate the fact that 2FA is available with the service. Everyone should have it turned on for any high-value mail account they own, Google or no-Google.


Take a look at, for example, "Abuse at Scale" from the Gmail folks at April's RIPE conference for an idea of the threat.

https://ripe64.ripe.net/presentations/48-AbuseAtScale.pdf

1 million+ bogus authentication attempts per day, 60-100k auths per second (legit and not), etc.


That's definitely an eyeopener. Gracias.


Well, ideally, 2factor should be used for anything with sensitive information... Frankly, I wish I could have enabled 2factor waaaaay earlier on GMail.


I take it you've never had your email account hacked, then?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: