Hacker News new | ask | show | jobs
by forgotusername 5121 days ago
> Here are some things you should do immediately: create a unique password that has a good mix of capital and lowercase letters, as well punctuation marks and numbers; enable 2-step verification as additional security; and update your browser, operating system, plugins, and document editors. Attackers often send links to fake sign-in pages to try to steal your password, so be careful about where you sign in to Google and look for https://accounts.google.com/ in your browser bar. These warnings are not being shown because Google’s internal systems have been compromised or because of a particular attack.

How does any of this differ from regular user advice? And note the last sentence, they are explicitly admitting the warning relates to nothing in reality beyond the normal environment. Do we suppose that people in China aren't aware their government spies on them? Do you suppose your own government does not?

I don't understand why this banner isn't shown to all users - China or otherwise, or why show it at all. Do something actionable and meaningful - introduce password complexity requirements, mandatory 2 factor authentication, require use of a signed browser with pinned SSL certificates - anything but non-specific nonsense that does little but promote unactionable fear in the hearts of thousands of users.

1 comments

Don't forget that government officials, defense contractors, etc. also use Google products. Not all hacking is criminal or local. Some of it is geopolitical in nature.