Skip to main content

Security or complication? Google Device Account and Emergency Email

I've had a Gmail account since they were introduced. I have an easy to remember account name, and Gmail includes a lot of nice features like checking other accounts via POP3, mail forwarding, and mail filters. They also have the best spam filter I've been able to find. As a result, a few years ago, I started sending all of my email through Gmail just to deal with the spam.

To their credit, Google offers really great security for Google accounts. They came out with Google Authenticator a while ago, and they support U2F and other common two-factor authentication. They make it easy to see which applications have access to different parts of your google account and what bits of data have been accessed. It's all well thought out and quite secure. Except...

Google makes Android available to anyone. The core portion is Open Source, and they license a lot of the add-ons under a pretty open license. As a result, lots of companies make Android devices. Unfortunately, those companies do not have the same focus on or understanding of security as Google. Most of the Android phone makers have had significant vulnerabilities, and they tend to be slow about patching them.

As a result, there's one giant hole in Google's security armor: devices. When you authorize a device like a phone or a TV, that device gets full access to everything in your Google account. Your $20 Walmart cell phone can read, delete, or forward all of your mail. So can that Android TV that hasn't updated in a year. And, the Internet of Things (IoT) is here. Everybody wants to make "smart" lamps, coffee machines, door locks (!), etc. And by "smart", they mean, "vulnerable to anyone in the world with an internet connection." My TV wants me to sign in with my Google account. My printer wants me to sign in with my Google account. My router wants me to sign in with my Google account. My wireless light switch wants to use my Google account. And if any one of those devices is compromised, there goes more than a decade worth of email, including not just the last messages from a few people who are no longer here, but messages from my bank, my retirement account, and from the government.

As a way to mitigate some of this risk, I've taken two steps:

First, I created a Google account for my devices, and I added the device account to our Google Families group. That way, I can log in to the TV with the device account and the TV can still show movies that I've purchased with my own account. But, if the TV is compromised, it won't have access to my main Google account. The same for printers, routers, tablets, etc. Unfortunately, it does make ordering new movies more complicated.

The other thing I've done is to create an "Important stuff" email address at Protonmail. Protonmail is very concerned about security, and their design is pretty good. I've enabled two-factor authentication (they use Google Authenticator, so I didn't even have to install a new app), and I don't give out that address to anyone except my bank, government, tax people, etc. If a missed message could ruin my life or get me thrown in jail, it's sent there. It's also the backup address for my Gmail account, my cell phone carrier, and my ISP. And, since I don't use it for routine mail, almost every message to that address is important. Protonmail even has a nice feature where, if a message comes in and I don't check it for 24 hours, they'll send a reminder to my Gmail address.

The downside: Now, I have two more accounts to keep an eye on. Two more sets of usernames, passwords, and Google Authenticator keys to track.

Will this be more secure? I don't know. It feels like I've limited exposure and segregated roles, which is a good security pattern. But, it might just be more complicated. I guess time will tell.

Comments

Post a Comment

Popular posts from this blog

The Virus By the Numbers

I'm writing this because there's some really insane stuff that's being said by people who should really know better, and I'm sick of discussing it one post or email at a time. So, this is my One Big Post that I'll point people toward rather than bringing it up again and again. In case you haven't noticed, we're in the middle of a pandemic. Just so that we're all using the same terminology:  The virus is Severe acute respiratory syndrome Coronavirus 2 . It's usually abbreviated SARS-CoV-2. It's a brand new kind of Coronavirus, so for a while, before it had this awkward name, people were calling it "novel coronavirus". (For the non-English speakers and D students, "novel" is another word for "new".) The disease that the virus causes is called Coronavirus Disease 2019 , and it's usually abbreviated COVID-19. It's called that because it was discovered in 2019. This came out of nowhere in China in late

The Chromecast conceptual model

Google makes a device called Chromecast . It's a relatively inexpensive way to turn any TV into a "Smart" TV capable of playing movies or music. It's a clever bit of engineering, but I've run into a few people who have trouble understanding how they work. The key thing to understand is that the Chromecast is the device that's actually receiving and playing the movie (or whatever), and your phone is just the remote. Here's how the process works at a high level: You start watching a video on Youtube 30 seconds in, you decide that you'd like to watch the rest on your TV, so you press the "Cast" button. Your phone stops playing and tells the Chromecast "Get this video directly from Youtube and start playing at the 0:30 mark"  When your phone initially asks the Chromecast to start playing, it also specifies a "default thing" to do when the Chromecast is finished. If the Chromecast is playing a Youtube video, it might

Audio upgrade: Schiit Fulla 2

I recently purchased a Schiit Fulla 2 . I was on the fence about it for a long time, but it's held up well, and I'm pretty happy with it. So, here's a small product review. I should probably mention that I'm generally skeptical about "audiophile" anything. I've known too many people who spend way too much money on voodoo like "oxygen-free speaker cables". This makes me reluctant to trust reviews or spend money on anything that I can't test for myself.  I've heard good audio. I go to concerts. I know what music is  supposed to  sound like, and it wasn't what I was getting from any of my computers, even with decent headphones, lossless audio codecs, etc. On the other hand, we have some  Sonos speakers , and with those speakers and a good audio source, music can sound really good. Since I wasn't getting that level of quality at the computer, it meant that there was something between the computer and my ears that was part of