29 ms·
Tell HN: Lost then regained access to Google account, with correct credentials
"Google couldn’t verify this account belongs to you."
I clear cookies once in a while and usually can recover my account but this time, no option to recover:
https://i.imgur.com/vb1mliN.png
Even if I have the correct login and password.
Luckily, I forward all my emails to a 3rd party so I should still be able to read my new mail but I lost access to a lot of other stuff.
Edit: Account recovered. I used chromium to login (which I never do) and then back to Firefox.
- JamesAdir 5y agoAbout a week ago there was a trending article about backup strategies in HN and everyone shared their insight. But it seems that know one takes thought about backing up your personal cloud services, especially from Google. There have been countless stories of people locking out from their Google account and still people don't do some basic backing up.
- em-bee 5y agoi use firefox containers for critical logins like that, where i never clear the cookies.
- decrypt 5y agoI ran into a variant of this issue: I received an email at my primary address (recovery address for Google) that someone is attempting to log into my old Google account, and that the request was blocked. I try to reset password, hoping that the reset link is sent to my recovery address but Google doesn't allow that. The only option is to "try and enter the last password I remember". Besides that there's no way to reset the password. Why even bother informing me at my recovery address about the suspicious login then? As long as a recovery address exists, it must be able to reset password?
- authed 5y agoGood idea, but when I try to reset the password, it asks me for the last password I remember https://i.imgur.com/vedOeJG.png https://i.imgur.com/vedOeJG.png and then I am brought back to the same page https://i.imgur.com/JAXxcvl.png https://i.imgur.com/JAXxcvl.png ... (I tried my current password and the last two before that).
- cr3ative 5y agoTry a different machine and a different internet connection. Maybe your phone - just a nice normal everyone-has-one machine - if you're on an anonymous or strange version of Linux, or using a VPN, or datacenter internet connection etc, they might be blocking you automatically. I'm not saying that's good behaviour on their part but it looks that way.
- decrypt 5y agoWell, that's not good. It's frustrating that there isn't a customer support division that you can talk to either, at least for escalated issues like the ones we face.
- authed 5y agoyeah not good... and the only reason I started to save my previous passwords is because of Google. It is the only company that I know of that uses obsolete data to verify that you are the account holder.
- cunthorpe 5y agoThis kind of stuff ought to be regulated somehow, one can’t lose access to one’s life. I recently wasn’t able to recover an old account because I did not have access to my 2FA number and their help site suggested I “contact the phone company to recover the number, then try again.” I had to do the same exact thing for another service but they did allow me to change the number by providing some information like last transaction, ID, selfie with statement.
- dangerface 5y agoYup lost my phone for a few months until my provider deleted my number and moved it on to some one else, now I am locked out of my paypal. I tried to find a pay as you go sim where the number doesn't expire and I would use that exclusively for 2FA but such a sim does not exist in the UK, most expire after 3 months the longest is 6 months. Now I know this is an issue but it doesn't seem like there is anything I can do to solve it.
- decrypt 5y agoYou could avoid using SMS for 2FA. Most websites offer TOTP as first choice for 2FA. For the ones that insist on SMS 2FA being first choice, I don't bother using anymore. I delete the account and find another provider.
- ylere 5y ago"most websites" has not been my experience at all. Sure, for the big ones like email that's and a lot of dev tooling that's the case. But there's a huge amount of services that requires SMS verification and once you loose access to that number you get locked out. A very common case is loosing ones phone (or having it stolen), at which point you have to log into your accounts again from another device but also don't have access to your SIM anymore.
- jonathantf2 5y agoThe NHS requires SMS 2FA - can't get around that.
- bavxo 5y agoLog in from one of the ip ranges and browser/os combinations you’ve used in the past
- authed 5y agoI am on the same internet connection (Comcast cable) but my IP address did just change though. Edit: I was able to login using Chromium (even if I never usually do)... and now it works again in Firefox. I wish Google would just accept my credentials and ignore the rest.
- hansel_der 5y agoHN exposure to the rescue! https://xkcd.com/806/ https://xkcd.com/806/
- mrweasel 5y agoI love that, because it's sadly very relatable. We had to create support ticket for a defective server. It was impossible to move the "support" forward, because we didn't know if the server smelt burned. In the end we just said: "Sure whatever, it smelt like burned electronics."
- spoonsearch 5y agoI too faced the exact same issue, lost 2FA recovery codes as it was saved in Google Drive (lol). The most frustrating thing was that even though my phone number was linked to my Google Account, they didn't have an option to send OTP to my phone number to reset my password. Even after contacting Google support nothing helped, eventually I gave up and created a new account :/
- ceejayoz 5y ago> they didn't have an option to send OTP to my phone number to reset my password This is good, really. https://en.wikipedia.org/wiki/SIM_swap_scam https://en.wikipedia.org/wiki/SIM_swap_scam
- deleted 5y ago[deleted]
- authed 5y agoFixed. I used Chromium to login (which I never do) and then back to Firefox. Everything back to normal, for now.
- DoingIsLearning 5y agoSo I have also had this happen to me in the past which was one of the reasons I abandoned gmail completely. Am I understanding this right that you had the correct password but no 2FA authentication and somehow a Firefox user agent on Linux triggered google mail servers to shut you out? I never really tried with chromium perhaps I can still retrieve old data (Google Support was obviously non existing on this issue).
- authed 5y agoYes I had the correct password and no 2FA... yet they require some form of second-factor that I am not really aware of.
- aj3 5y agoIt's not user agent, it's session (cookies, localStorage) that they didn't have in Firefox, but still had in Chromium. And this isn't Google specific at all.
- DoingIsLearning 5y agoBut they just said they cleared cookies. Also I travel a fair share (used to) and never faced any issues with any other services except gmail. It's too stringent to assume the same machine/storage/ip are always used.
- aj3 5y agoRight. Session is stored either in cookies or in Local Storage. Both get cleared when you "clean cookies". If there is no device session, next time you're trying to log in, service will ask to show the second factor (so that hacker can't steal your account through finding the password on some other website). Firefox didn't work, because person deleted session and didn't have second factor (nor backup auth methods). Chromium worked, because it still had device session. I'm traveling and using TOR and VPNs just like everybody else and haven't faced any issues. There most definitely is a problem with communicating security/accessibility tradeoffs to the public though, so I'm not putting blame on the op here.
- cmaggiulli 5y agoI have so many important accounts attached to my gmail so I created a bunch of backup codes and hide them in various places
- authed 5y agoGood idea, but I wish that there was an option to get backup codes without having to enable 2-step verification. https://support.google.com/accounts/answer/1187538?hl=en&co=GENIE.Platform%3DDesktop https://support.google.com/accounts/answer/1187538?hl=en&co=...
- Alex3917 5y agoBackup codes are a way to bypass the 2nd step, so what works that even mean?
- londons_explore 5y agoNo - you need backup codes and something else, like a password, SMS OTP, or access to the recovery email address.
- aj3 5y agoWell yeah. If the recovery process is weaker than regular authentication, that's what bad guys will use for account takeover. You don't want to lose Gmail because someone bruteforced your backup code?
- authed 5y agoIt would not be weaker then usual authentication... you would still need username and password. Not sure why companies nowadays rely on your tiny device to provide a second password. Both my passwords and 2FAs are on that device, what security does it add? And why do they need a password if they are going to require Timestamped-2FAs anyways?
- zevv 5y agoYou get what you pay for. (Sorry for the obviously totally useless comment that is not helpful in any way. But seriously: I've seen this happen to a number of people, and you're just out of luck - computer says no. If you value your digital history, host your mail and file at a party where you pay for the service - that makes you a customer not a product)
- everybodyknows 5y ago"Catastrophic” hack on email provider destroys almost two decades of data: https://news.ycombinator.com/item?id=19146110 https://news.ycombinator.com/item?id=19146110
- aNoob7000 5y agoI couldn't agree with you more. People complain about free services like if they were directly paying for it. I have my main email service through Protonmail and my GMail account is for all the spamming email stuff.
- jeltz 5y agoIt is not like you get much better service when you pay for Gmail. Maybe huge customers do, but small ones are treated almost like free users.
- hk__2 5y ago> If you value your digital history, host your mail and file at a party where you pay for the service - that makes you a customer not a product And then the hosting company has a fire in their datacenter and there’s someone on HN saying it’s still your fault because you needed to do backups as well. And then you have a backup issue and there’s someone on HN saying it’s still your fault for some other reason. https://www.reuters.com/article/us-france-ovh-fire-idUSKBN2B20NU https://www.reuters.com/article/us-france-ovh-fire-idUSKBN2B...
- Ensorceled 5y agoThere is always someone on HN willing to blame the victim and excuse, or at least shrug at, the bad behaviour of trillion dollar tech companies.
- mathieubordere 5y agoI perform a periodical backup of all my Google data with https://takeout.google.com/ https://takeout.google.com/ if the sh*t would ever hit the fan.
- karpour 5y agoIs there a good way to automate this?
- skyeto 5y agoIt lets you choose a bi-monthly schedule for the exports, then you just need to automate the download from the link that you get emailed.
- deleted 5y ago[deleted]
- lelandfe 5y agoNo API but you could script the browser. Obviously would break if the UI changes. Quick google shows some potentially still-relevant posts: https://superuser.com/q/716756 https://superuser.com/q/716756
- msh 5y agoGoogle takeout offers build in automation, you can set it to run every X months automatically.
- sschueller 5y agoI have been looking into this. There is mbsync (isync)[1] which will let you download a imap account. There is also a premade docker image[2] which you could trigger via cron and sync your mails. For gmail it is recommended to get a login token but I have not looked into how to do that. [1] https://isync.sourceforge.io/mbsync.html https://isync.sourceforge.io/mbsync.html [2] https://github.com/JakeWharton/docker-mbsync https://github.com/JakeWharton/docker-mbsync
- JamesAdir 5y agoI hope you checked your data and tried to restore everything. I pulled out my Google Music data about 6 months ago and it was almost unusable with Google mixing all the data in one folder.
- swiley 5y agoYup. This happened to me two years ago. Thankfully I hardly used them for anything important. They started freaking me out years ago and I've moved to self host everything. People still send emails to my gmail address, including my own family. It forwards to swiley.net for now but that probably won't last.
- mihamaker 5y agoI lost a lot of accounts because of this misunderstanding. I always use a VPN for work. I keep all logins and passwords in the password manager. But Google is very worried about my safety, even to my detriment.
- authed 5y agoSame. I don't even know my password, but I know that I have the correct one because I use a password manager.
- 300bps 5y agoKind of like 90% of the problems on our production servers at work over the last ten years have been related to security software installed on them.
- donmcronald 5y agoUsing a public VPN is almost guaranteed to flag your logins as suspicious at all of the big tech companies. If anyone wants to see how intent big tech is on tying your profiles back to personally identifiable information, connect to a VPN and try to create new accounts on various services. It's basically impossible without a non-VOIP phone number. If you manage to get an email address, big sites like Facebook and Twitter will instantly lock your account and require SMS verification. Big tech discriminates against anyone that doesn't have enough money to own a phone.
- obiwan14 5y agoHave you tried to create an account at this site - HN, using a Tor-enabled browser of over a VPN connection?
- cachvico 5y agoIsn't that just a necessary measure to stop bots?
- hbn 5y agoWhenever I'm connected to my VPN (I use Private Internet Access), Google will force me to pass a captcha test every time I do a search
- grammarnazzzi 5y agoGoogle marketing: "Entrust your livelihood to us because we're the experts" Goodle production: "We're not responsible for your livelihood" Same from Microsoft
- aj3 5y agoClueless users: "Let me enable uber-secure mode, so nobody can hack me" Clueless users next day: "Damn, I got locked out of my account, there are no alternative email addresses for recovery, I lost Ubikey and didn't save backup codes"
- znpy 5y agoI wonder if you could sue google to get back your data. They have your data and they are effectively arbitrarily deciding you can't access them anymore.
- htrp 5y agorealistically, you threatening to sue would get you transferred to an actual human being to resolve this you may have to get a letter from an actual lawyer
- varispeed 5y agoThey are too powerful. Nobody stands a chance against their infinite budget and top lawyers.
- znpy 5y agoI don't buy that
- hk1337 5y agoSo, what was the cause of your inability to login sense all you did was switch browsers for it to work? Could it be some autofill or other cached information jacking with the form input?
- aj3 5y agoMost probably they've added MFA and lost it. Devices that have been authenticated already can be used with the bare login & password, but new sessions will ask for the MFA they can't access.
- dt3ft 5y agoThis story keeps coming up. When you pay for email, you get a customer status. This entails a SLA and a bunch of other rights, which you most likely never get from a free service provider. I hope if those reading these comments still use free email service instead of hosting their own (or paying for it), strongly consider making the switch.
- zerr 5y agoIs it necessary to pay with a fiat currency to be considered as customer? Paying them with personal data doesn't count?
- hackflip 5y agoIs a pig the farm's customer when they "pay" with their flesh?
- dorianmariefr 5y agoThere is Google Workplace where you pay $5/month/user for a google account including email and there is support
- alvarlagerlof 5y agoCan you even use that if you're not logged in?
- decrypt 5y agoCould you elaborate on what you mean by "use"?
- NikolaNovak 5y agoHow do you gain meaningful access to help/support without being able to sign-in to their help portal / ticket system? I've been exposed to that type of Kafkian catch-22 nightmare scenario all too many times :|
- S5yDyAk3XoQH5 5y agoYep I have an account like that for several years, but it's still logged into thunderbird and works fine for sending / receiving. Cannot login via browser though. It asks for my recovery email, which successfully sends an email, and then says "we cannot verify it's you" lmao
- corporealfunk 5y agoThis has happened to me too, but in my case the Google account that I lost access to is the admin account of a Google Adsense publisher account. For some reason I don't receive the 2FA code to my phone, though I do know the recovery email address and the password. I don't log into the Adsense account a lot, it's a small amount of revenue, enough to cover some DO droplets every month. Given that I don't log in a lot, between my last login and first getting locked out, I had switched ISPs and switched my main browser to FF from Chrome, and even erased all my old Chrome data. So, new IP, and no cookies/fingerprint, not getting the 2FA codes... lock out! No recourse. No person to ask. What's more funny is that I figured, well, I'll just create a new Google account and sign up for Adsense again for my domain with the new account. Turns out you can't do that because the domain for the Adsense account "is already in use by another Adsense account". There is simply no customer service.
- MagnumOpus 5y agoSue them in small claims court, it's cheap and it sends a message. Worth it for the satisfaction even if the Adsense revenue they scammed from you is less than the (small) filing fee...
- teh_klev 5y agoI had a bit of a squeaky bum moment the other night. I needed to sign up for Stadia and was asked for my gmail address and password which for the life of me I couldn't remember (and it wasn't in my password manager). I then requested a password reset and tried a couple of the account rescue codes. Turns out I'd used these specific ones before but hadn't marked them as used (doh!) and at that point stopped in case of a hard lockout due to "suspicious activity". So at this point I capitulated and just went for the "I'm dumb and forgot my password and have no other codes or keys" option. I was then told it'd take SIX HOURS for google to verify my account before they'd send me a password reset link. Luckily it all worked out and all I lost was an evening of Stadia, but I couldn't help feeling I was teetering on the edge of loosing my account. Footnote: yes I have considered switching to a paid service such as Proton Mail, but at the time covid happened, I lost my income and couldn't afford it. I think this experience will spur me on now that I'm gainfully employed.
- ttybird 5y agoI hate this. If I know the password I should be able to log in to my account no matter what (unless if I have 2fa enabled). Sadly companies like Google and MS do not like this idea, they also often use the excuse that they can't verify you in order to mine your phone number. "Edit: Account recovered. I used chromium to login (which I never do) and then back to Firefox" How can google keep getting away with this? MS got into trouble with IE with much less.
- sharklazer 5y agoKeyhole, Jigsaw. Deep ties to defense.
- junon 5y agoGoogle denying me access to YouTube videos asking me to verify my age by giving them either my passport or my credit card should be illegal as well. Then they expanded it to the app store - some apps, even ones that don't seem to need to be age restricted - now require I verify my age in the same way. I just give them the middle finger and manually install the APKs for those apps. Unfortunately, no way to get around the YouTube restriction though. Google having a complete monopoly on this stuff has got to end at some point. They have way too much power over what are now pretty mainstream services to the internet, especially since they cannot be completed with by most companies, even those with adequate funding and reach.
- kevincox 5y ago> Google denying me access to YouTube videos asking me to verify my age by giving them either my passport or my credit card should be illegal as well. Wasn't this added because of some EU law? It seems that YouTube's interpretation was that asking this is the opposite of illegal, actually legally required.
- mc_woods 5y agoUK prawn laws? - proposed and then dropped?
- 5y ago
- waltbosz 5y agoThis reminds me of the time that I obtained my original cleartext password for my old tripod.com account by simply emailing their tech support from an email account not associated with the tripod account. The email address from which I contacted them had the same username as my tripod account email, just at a different domain. Their response email was simply my password. Not a password reset link, not a new random password. No questions asked. This happened less than 5 years ago, when password hashing should be standard practice. But tripod was created in the 1990s when it wasn't standard, and I guess there was no budget/willingness to refactor the old database and login code. I was not surprised to hear a few years later that their cleartext password database had been hacked and published.
- jayolden 5y agoThis happened to me when I was away from my home; I tried to log in to my Google account, but I couldn't gain any access; I tried to change the password and everything, yet the email won't update; it will only update on my browser.
- absolute-evil 5y agoHi, this account was created for this post. My personal gmail beta account is to this day being held ransom by Google. It was only used for my most important accounts, my bank, gov, utilities etc. My life, online and offline. Despite only ever logging in from a residential line in the same city for entire life of the account; one day there was """suspicious activity""". I did everything asked.. confirmed every detail, provided backup codes, secret answers, gave up phone numbers, every password change and dates, even the exact date and location when the account was created, E V E R Y T H I N G. Turns out that my account is so secure that even I cannot access it. Well I'm sure you can imagine what a total fucking nightmare it was to workaround the absolute evil that is Google. That's my rant, I'm glad that you got your account back OP.
- mc_woods 5y agoYou've just reminded me of how much I rely upon a free service provide something so critical to my everyday life. Time to move to a paid service where I can have someone to call when issues like this turn up.
- datavirtue 5y agoI have had my domain/email hosted on office 365 for years now. Zero issues. Before that I hosted it through various other providers which was also fairly trouble-free. Many years ago I tried hosting my own email server. That excersize revealed how cheap $50 a month is to have email hosted for you. Recently, I became a "Microsoft Partner" which gets you a monthly Azure allowance, software licenses, and five Enterprise accounts for Office365. This is only $550 a year which is cheaper than my previous office365 small business account. The support is great when or if you need it. You probably will.
- zoe4883 5y agoBackups? I have daily snapshots going back 1 month.
- Andrew_nenakhov 5y agoHappened to me on an account I didn't use for a couple of years. I used the same IP, login, password, recovery email. Nope, 'we can't verify it's you, try again later'. Later I tried, and tried, and tried for a few weeks, still the same. I gave up, transferred all services linked to this email, with some back and forth with their support. Then, after a couple of month of not trying I was finally allowed in. The moral is this: google can't be trusted with such serious and vital service as email. They can freeze your access to an account and offer no way or support to let you back in.
- anter 5y agoHappened to me as well, except I could never get back the access. This is how it permanently looks like: https://i.imgur.com/4YrElkJ.png https://i.imgur.com/4YrElkJ.png
- authed 5y agoI don't like it when you replace my title and make it confusing.. almost seems like I only had the correct credentials when I regained access (dang)