HN user

forgottenpasswd

2 karma
Posts0
Comments2
View on HN
No posts found.

I'm amused that some commenters (here and at TechCrunch) are accusing Google as the primary fault. I would say the opposite. Gmail is not perfect, but it has plenty of security measures compared to other mail services.

For most users, the idea of that kind of password reset is convenient. And it's not easy as you claim nor practical to regularly check the existence of alternate emails, especially with the amount of users Gmail have. And by the way, they already have a new feature wherein you can use your mobile number to retrieve a password reset code.

There is a feature in Gmail where you can see other currently and some previously logged in sessions. Perhaps it can be made more visible to the user, but it worked for me and had actually used it once to halt an intrusion (not really hacked, my password was automatically saved from another computer's Firefox).

Lastly, another feature that makes me feel safer with Gmail is HTTPS and the ability to force your session to HTTPS whenever you log in.

Disregarding the human "holes", I think the biggest hole here is Hotmail allowing expired accounts' usernames to be registered again. That should be a no-no considering the importance of the use of email as an identity. They can purge the account as it expires, but they should not let others use the username again.

Most others are just "best practices" that try to keep balance between security and usability. Except for the practice of emailing a password in clear text which compromises a lot of security for little usability gain.