5 ms·
About a month ago, a hacker guessed a weak password on one of my seldom-used Google accounts. They changed the password and the recovery email. I attempted to
by flaxton 7y ago
About a month ago, a hacker guessed a weak password on one of my seldom-used Google accounts. They changed the password and the recovery email.
I attempted to get the account back, including telling them the old password, old recovery email, and the month and year I opened the account (like 10 years ago) but no, they said they “couldn’t” do it.
So I’m sunk. No recourse, no one to appeal to.
So why would I put my whole life into Google? When it can be taken away so quickly, and there is no appeal process?
On my main Google account I do have a recovery email (that I host) and 2FA. But I do not feel secure that the same thing couldn’t happen there too.
If it does, you are sunk.
I’m actually in the process of moving everything off of Google.
No thanks!
- graeme 7y agoCompanies really need some sort of rollback to prior recovery email option. I had this happen with an old skype account I hadn’t put 2fa on. I was able to get back into the account, but since the attacker had added their email, any changes had to be confirmed via that new email address! I re-entered a few times but eventually just gave it up to them. Microsoft was no help.
- vezycash 7y agoOutlook now has a wait period of 30 days before some certain security changes can be made - e.g. account recovery options. I've never used it though. https://support.microsoft.com/en-my/help/4057241/microsoft-account-why-does-resetting-security-info-take-30-days https://support.microsoft.com/en-my/help/4057241/microsoft-a...
- graeme 7y agoThat's exactly what caught me I think! Because the user changed the email, I couldn't change it back for 30 days. I may have been an edge case: I had no email on the skype account, only a recovery email. Eg: Account email: null Recovery email: myemail@example.com The hacker changed it to: Account email: hacker@example.com Recovery email: null My account was old enough they hadn't required an account email on creation. My ownership of the old recovery email was not persuasive to microsoft. I was even telling them about it while the hack was happening. They let the hacker take over fully, send spam, and shut down the account for spam. Basically I couldn't change the account email for 30 days, and the hacker had been able to remove the recovery email.
- adrianmonk 7y agoI don't see how you could do that without opening up another risk. Suppose your recovery email account is compromised. You don't want it as a recovery email anymore because then the attacker can use it as a foothold to get into this account. If you can roll back removal, then you can't protect against that. The only way I can see around that is if there are conditions on rolling back. But then if you're going to require authorization to roll back, you need to authenticate that request, and the whole reason you're trying to do this is because you are trying to reestablish the ability to authorize.
- pas 7y agoYou could be the hacker who got hold of the old recovery email. :/ There's no safe way to do these recovery processes. Weak/lost/compromised password means that, the account is gone. Sure it'd be nice to have a fallback that ties recovery to visiting an office, where you establish some shared secrets, biomarkers, etc. But big companies are not into that because probably too few people pay for this. (As they also don't want to depend on a 3rd party for identity management.)
- klipt 7y ago> There's no safe way to do these recovery processes. Imagine if banks said the same thing. "Oh someone changed the password and email on your bank account, sorry you permanently lost access to all that money." If you signed up with your real name, some combination of government id, proof of physical address etc should be enough for recovery. If it's good enough for banks, shouldn't it be good enough for email?
- oefrha 7y agoOkay, so you’re proposing that Google ask for your government ID when you sign up for a Gmail account?
- theli0nheart 7y agoYour comment seems a little aggressive, but that notwithstanding, there is the option of letting users allow it only if they wanted some extra security. 2FA and other safety-related items are optional...so why couldn't this be?
- kijin 7y agoIt doesn't even need to be government ID. As soon as you pay for something, like starting a Google One subscription or buying an app on the Play Store, your billing information should establish your identity. Later when you need to get your account back, you may need to present some sort of government ID and/or proof of address that matches your billing information. It's not bulletproof but it's better than losing access to a paid account forever.
- cryptozeus 7y agoWell you are using free resources that is why. If you had paid account with them then they will of course help you get it back. Google one is different then getting free inbox.
- raverbashing 7y agoA seamless account recovery was absolutely not the experience some people I knew had with paid Google Apps or other paid Google products accounts. (Not to mentioned the unexplained account locking) So, no, it's not merely an issue of "just paying".
- GuB-42 7y agoThat's a hard problem. Think of it the opposite way. You just changed your recovery e-mail and password because your recovery e-mail was compromised, and you also used the same password. In other words, you secured your account. Maybe you setup 2FA and a bunch of other things... good. Now take the place of the attacker. You look at the compromised inbox, see a confirmation email from Google. Nice, you now have an account login, the creation date, and a good password candidate. If you could simply call Google, give the info you already got by reading the compromised mail, and get access, no amount of securing done by the victim could work. There are two contradicting goals here: keeping your data secure from hackers, and allow some mistakes to be made on your side without you getting screwed (using a weak password is a mistake). Google is constantly juggling between the two and sometimes, the outcome is not what you want it to be. The solution is not to hold on your personal data too much. Google doesn't ask for it only so that they can target you with ads, even though it is a very important reason to them. It is also used to secure your account. If you don't want to use Google, good, however, there is no perfect solution, especially if you are not flawless yourself. Keep data on your own machine? Do you have offsite backups? End-to-end encrypted, privacy focused services provide no form of password recovery whatsoever. And services that are a bit too loose may give anyone access with a bit of social engineering. Pick your poison.
- deleted 7y ago[deleted]