Also is it only domain block and not ip block?
[0] https://medium.com/@N/how-i-lost-my-50-000-twitter-username-...
Apparently he's got his @N account back. I wonder how it happened, I don't see anything about it in the article.
Should be good enough protection against social engineering targeting registrars.
If your mail provider runs into problems or you choose to change, then instead of waiting for DNS to propagate, you simply update your relay configuration.
I should add that not all paid mail providers support this. Some lower-end providers require that you point your MX directly to them. Check before setting this up.
If they can MITM you, why not steal the password directly, or serve malicious js to get your password?
https://security.stackexchange.com/questions/29988/what-is-c...
My point was that MITMing HTTPS and HSTS isn't really necessary to carry out an attack as described by the root comment.
You only need to be in position to eavesdrop and/or MITM http connections to scrape together the necessary information; a much lower bar.
Same here. I gave them everything there is to identify me yet they refused to help on the same grounds. The only difference was the phone number, because the one associated with the account died. Funny thing is, if it were not for an accidental removal of cookies, I would still be using that account, and I would have been able to login as it only seems to ask for the code sent via SMS is when you lose your cookies and/or change your user agent.
I switched to protonmail for non-serious e-mails.
Last year I was working on a service that skipped passwords altogether. We used the phone number and a one time pin code by sms for registration, login and order confirmation all in one step.
Kind of legit to be honest. Anything else would make it far too easy to recover accounts. Also Gmail is far too large to have a customer care that could also do things like passport verification or so.
Having said that, Protonmail has no phone number recovery. That's kind of bad. You can enter an old E-Mail address there though but it would be so much better to link this with a phone number. If you loose your sim card, you can always get a new one from the phone company with your passport.
Why is being able to recover accounts easily a bad thing when you, and only you have or should have access to, say, the password?
> Protonmail has no phone number recovery. That's kind of bad
I do not use it, so it is fine by me.
> If you loose your sim card, you can always get a new one from the phone company with your passport.
Not necessarily. It is more and more difficult to get a new one, and there are prerequisites that one may not meet, or they decide they do not want to do business with you, or your social credit is too low, etc.
The differences are: one is given to you by a third party, and the other one is made up by you.
I would like to be able to opt out of it, e.g. phone number should not be required.
Considering how many high profile bitcoin thefts occured using hijacked phone numbers, it's probably better not to have that as a reset method.
Most users don't even have Bitcoin but normal bank account which are oftentimes protected by different second factors. It would be nice if they would provide different options. For me it would suck if someone hacked my E-Mail but I could reclaim it quickly and the damage would be very limited.
Once one of my Google Accounts was taken over by a hacker (I had reused the password on another site, which was hacked around that time), and even although Google warned me that someone was trying to take over my account, and told me someone was logging in from Russia (I always logged in from the exact same IP address from which I tried to recover it), and even though a friend at Google submitted an internal request to get me the account back, and even though I sent them a photo of my ID (with the Google account having that exact name in it), they refused to help me.
Google support did try to reach out to me, as I later figured out, but they had instead contacted me via the hacked email account, I only found the "thanks for your support chat" mail in the account after I regained access.
Which I was only able to do so by talking to the person who now owned the phone number I had used a decade before for that account (the ISP had long recycled it).
Thinking of ditching the ~tracking device~ phone anyway... what then? Have we sleep-walked into a world where people without a mobile phone are the underclass who barely even exist?
As a "technical" person, I despise passwords and tend to avoid using them. My preferred way to log-in somewhere is either with ssh keys or with single-usage codes sent by mail.
This has nothing to do with "losing" passwords. For example, I actually have a password for amazon written in a file, but I don't bother looking for it, I prefer to use the single-usage code anytime I want to use the site.
Simple use case. You create an account while on VPN. You don't provide a phone. Then you clear your cookies. That's it. If your exit point IP changes, Google will not allow you to log back in even if you know the password.
Interestingly, the original meaning of "third world" country was: a country that is neither part of the Soviet block nor the US side ( the two first worlds)
"Probably someone read the news and googled protonmail, saw "encrypted email" in Wikipedia page and decided to block the whole thing." <-- where do you get that? it's complete nonsense
As for the complete nonsense you have something working for 5 years suddenly it gets news coverage with no significant usage increase and is blocked . I have no source but this is the exact case where I live. there's something ,like a publicity threshold.It sounds silly and irrational because it is silly and irrational. Or perhaps I am wrong and some experts were analyzing protonmail for 5 years and now came to the rational conclusion to block it.
Like a distant god, Google gives and Google takes away...