37 ms·
Ask HN: Gmail account security
I have a gmail account that I rarely use, but I know the password. I enter it correctly and get the following message:
You’re trying to sign in on a device Google doesn’t recognize, and we don’t have enough information to verify that it’s you. For your protection, you can’t sign in here right now.
Try again from a device or location where you’ve signed in before.
Even if I get the code from the recovery email account, it won't work. Is this the AI hell Google throws you into if you get a new phone and computer in the same year? Has anyone else on HN run into this and found a solution?
- dannyw 5y agoI signed into an old Gmail account of mine that had a bitcoin private key backup. After signing in successfully, I searched for "bitcoin private key" in Gmail. Within a second and before the search completed, I was immediately kicked out of all active sessions, and my account was locked.
- brongondwana 5y agoYeah, unfortunately that's exactly the kind of thing that a hacker would do upon getting access to an account. sigh.
- johnnyApplePRNG 5y agoWhy was this title edited from the original (which was "Gmail account security is insane") as submit by caseyf7? I understand editing titles to articles but self posts...???
- SMVS 5y agoI lost access to my primary Google account in this way, 10 years of mail and drive inaccessible, all sign Ins void, and I find Google hasn't supported account recovery for almost five years. I'd set inactive account recovery, so if I died my brother would get access six months later. That didn't happen either. Google is a joke.
- diegolyanky 5y agoThat's because you tried to sing in using a cell phone which is listed into a black list. Maybe your mac address or imei is being rejected because it was used to do some illegal thing. Be careful...
- pkilgore 5y agomailinabox.email fastmail.com if its that valuable to you, pay!
- ericls 5y agoWoo.. This happens to credit cards a lot, but in these cases, you can at least call the bank.
- thetrip 5y agoLast time I use Google services I can't delete my credit card too. So I cancelled that. Now all my accounts are somethingfunny.anumber@ just for comment music in YT.YT i good, I wonder how they will trash it.
- fuzzy2 5y agoJust out of curiosity, do you have two-factor authentication set up? Or the Gmail app on a mobile device? Or do you really just have the recovery account?
- pettycashstash2 5y agoI once forgot my gmail password. There was no way for me to recover it. Eventually I found it after 6 months, but it was a very difficult 6 months. bank emails, work emails, etc were in the google 7th circle of hell, and there was nothing I could do. I don't have any good advice for you really except is there a way you could vpn to a location closer to where you typically access gmail?
- bigiain 5y agoI have one of the old gsuite free accounts with a personal domain, so my backup plan for that for the last ~15 years has always been "if google graveyard gmail, at least I can but mail service elsewhere and update my MX records". Now they're going to start charging me for that, I'm considering which non-google mail option I will choose instead, I've been sticking with gmail against all my privacy and ethical objections, because it works so well and is free. It's no longer going to be free soon, and I'm pretty sure their competitors work as well as they do (or very close to), so I can _finally_ get over the inertia that's made me feel _almost_ bad enough to leave gmail but not quite bad enough to pay money or do the work required. Right now, it looks like Fastmail or Protonmail are going to get my money.
- ahnick 5y agoSo in theory if someone was to ever accidentally or intentionally reset the location info for where all gmail accounts have logged in from, then effectively everyone would be unable to access their gmail account?
- ipaddr 5y agoWorse, one day it just doesn't work.
- brazzy 5y agoIf that were to happen it would take about 5 minutes until this security feature would be deactivated.
- josephcsible 5y agoIf it happens to everyone then yes. But now imagine it happens to just you.
- cinntaile 5y agoIt's especially annoying that you can't turn this nonsense off. I had this happen to me when I was abroad, obviously with no way to recover when I was abroad and I needed access to certain mails. Nice feature.
- ncann 5y agoSame here, I got an email to my main mail account saying Google has blocked a login attempt to another old Gmail account of mine that I haven't used for a long time (the old account has the new account listed as the recovery email). So I tried to log in to that old account, and got the same message to "try again later". I tried a few more times over the next few weeks but always the same message. So even with the correct password and access to the recovery email I still can't log in to the old account, and there's no way to get around it. I just gave up.
- floatingatoll 5y agoTry in Chrome with all extensions disabled?
- newsbinator 5y agoThis happened to me. It was impossible to access my gMail account, knowing my username/password/recovery email/all recovery codes... until I returned to my home country / home address. Then gMail let me in.
- NoPie 5y agoI stopped using gmail. I pay for my own domain (approx $10 per year and subscribe a hosting service that costs about $4/month). The total cost is not much different from a paid google email which is about $50/year. If I happened to forget/lose all passwords (lost laptop, burned house etc.), I would probably need to deal with the hosting company who would try to identify me with my credit card or some other way (phone number, mailing a letter to my physical address on file). Nothing is absolutely secure but I think it is secure enough for me while I also have fair good chances to recover my lost access. I am not a big target to scammers anyway.
- judge2020 5y agoBTW A paid Google email via Workspace (previously G Suite) has gone up to $6/month/user, so $72 USD a year for a single user setup.
- 5ESS 5y agoIn most cases it’s easy to social engineer hosting company staff into granting unauthorized access (even the major ones) all it takes is a bit of know-how and maybe a photoshopped ID. The weakest link in any security stack is always the human element. The fact that Google makes it impossible to get in touch with a human is why I trust it.
- NoPie 5y agoIt can be done but it is not guaranteed. Smaller companies have more geeky staff who would be more suspicious and wouldn't let that easily to be had. They have more accountability. I hear that many accounts of celebrities get hacked and I wonder how? Apparently even with 2FA it is not that secure. Some countries let you order a replacement SIM quite easily and then it can get intercepted (maybe by stealing from mailbox or similarly). This appears to be a reason why google has been refusing access even with 2FA in place.
- NoPie 5y agoThe biggest risk I think is falling a victim of the scam. I usually get emails purportedly from my hosting provider (sometimes from my bank etc.) that I need to verify payment or something like that. Obviously they are fake but I can understand that even an attentive person can have a bad day and click on a malicious link and enter all required details. Google is probably better in filtering out such scam. And yet I wonder if it still happens often enough that they actively block login attempts if they are from unusual locations.
- exolymph 5y agoWasn't aware of this, but can't say I'm surprised. Personally, I'm still happy with Fastmail, which uses customer subscriptions fees to fund a professional support department, as well as contributing to email-related FOSS. (Among other things, obviously.)
- julianwachholz 5y agoLast week's news gave a lot of people the nudge they needed to finally migrate away from their legacy free GSuite accounts to something more reliable.
- devb 5y agoCan I ask which news? I'm already a happy Fastmail customer, just curious.
- JaimeThompson 5y agoThis [1] Neat fact, Google is yet to tell me they are making this change to my account. [1] https://arstechnica.com/gadgets/2022/01/google-tells-free-g-suite-users-pay-up-or-lose-your-account/ https://arstechnica.com/gadgets/2022/01/google-tells-free-g-...
- rootusrootus 5y agoYeah, I haven't gotten the official notification yet either. Maybe going in waves?
- julianwachholz 5y agoI disabled the GMail service in my GSuite account, will they honor the domain's current MX records? Because I know they don't for calendar invites.
- rootusrootus 5y agoNot that anyone will likely see this, but I just now finally got my notice from Google about this change.
- Andrew_nenakhov 5y agoHad this. It was telling me to try again 'later'. Ok, i did 'try later' every day for three weeks, and they didn't let me in. Using the very same IP address as I used to always access it, no less. Then, I gave up, moved all my services to another email account, and after 2 or 3 months tried logging in, and it suddenly allowed me to log in. Needless to say, I will never again use gmail for critically important things.
- jjcon 5y agoHad the same thing happen to me, I know the password, have access to the recovery email but Google won't let me login. Spent months in a support thread with Google and eventually gave up. Still really bummed about it tbh
- abider 5y ago> Needless to say, I will never again use gmail for critically important things. That's a hot take. If it was critically important, you'd have 2FA and a recovery phone number associated with it - which would have prevented you from getting stuck in a trust-fail situation to begin with. Use whatever service you want, but your takeaway from this situation is a bit absurd. Edit to add: I'm not saying Google's algorithm is perfect here, but relying on heuristic voodoo ("I use the same IP, so I should be fine") for "critically important things" instead of using well-established means of securing access to critically important things (e.g. 2FA, backup mobile number) is a bit insane.
- ethanbond 5y agoSomething can be critically important for a person to access on-demand and not be something they’re especially concerned about an attacker accessing. Two completely unrelated dimensions of access needs.
- M3L0NM4N 5y agoThey are not mutually exclusive. An attacker accessing a service can hinder or even completely stop your ability to access that service (i.e. change your password).
- nathias 5y agoI just accepted I can't get to that account anymore...
- reactspa 5y agoPreviously on HN: https://news.ycombinator.com/item?id=29801850 https://news.ycombinator.com/item?id=29801850
- akkartik 5y agoFrom 3 days ago: https://merveilles.town/@akkartik/107656797631193281 https://merveilles.town/@akkartik/107656797631193281 One less risk to worry about.
- secondaryacct 5y agoI always use the 2FA and whatever happens it seems to allow me back in. I would think this happens with a phone number too.
- golem14 5y agoThat doesn't help OP now, but I found it helpful to enable 2FA with Google Authenticator, and keep emergency backup codes in a safe place. It's slightly more hassle, but there are less 'soft AI' barriers between you and your successful login. I'd also suggest not to rely on a phone number as 2nd factor, it's not that super safe.
- anter 5y agoI'd suggest not to rely on google for anything you wouldn't want to lose.
- ddtaylor 5y ago2022 me agrees with you, but 2003 me getting an invite to GMail when it was a brand new service and essentially a completely different company with a different landscape didn't know better. Now I have nearly two decades of accounts and things tied to GMail =(
- xhkkffbf 5y agoGoogle Takeout is a pretty nice service still. It's good to back up your accounts regularly.
- nieve 5y agoUnfortunately Takeout doesn't really do anything to help with purchases.
- ddtaylor 5y agoI think the main problem with many people isn't so much the archive of email that they would lose from not using GMail anymore, it's the many years of accounts that are authenticated with it. There are literally hundreds of services I have that are registered to that e-mail address now.
- jumelles 5y agoI’d recommend a non-Google 2FA app. Microsoft has one, and Authy is popular. Personally I’m happy with OTP Auth. Some password managers can also handle 2FA, e.g. Strongbox.
- tptacek 5y agoI'm having a hard time getting my head wrapped around the idea of relying on Gmail (or any other online identity provider) without enabling 2-factor authentication. The best way to avoid this kind of "AI hell" is just to take control of your own account security and set up some additional factors.
- caseyf7 5y agoExcept Google does not honor the recovery account. Even with access to the recovery code, Gmail just ignores it.
- bawolff 5y agoRecently i wanted to setup a shared gmail account with some people. Even with 2FA setup, correct password correct TOTP, it did not let them in because it was suspicious. I also checked "it was me" in all their security alerts. It would only let the person in with sms based 2fa, which was a pain.
- rdtwo 5y agoGoogle will still lock you out with 2fa. It’s pretty bad
- m-p-3 5y agoEven with a FIDO2/U2F/WebAuthn key? If so, yeah that's pretty bad..
- rdtwo 5y agoYeah I got locked out dispite having printed codes and authy setup. Lasted a day or so
- m-p-3 5y agoThat's a scary thought, being locked out of a primary email address despite taking security seriously. I currently have it secured with my backup codes (printed and stored in a secure location), as well as two Yubikey (one primary, one backup). I'd be seriously angry if Google locked me out of my account.
- 2bitencryption 5y agoOh god, have you had the M.C. Escher-esque experience of trying to sign in to an email account, and it hits you with a two-factor-auth prompt that sent the code to another email address? Imagine the insanity if the email account that received the code in turn asks for a code sent a code to the first one.
- zamadatix 5y agoHaving 2 logins is still 1 factor, the situation is not insanity it's the designed intent of MFA you shouldn't get access in that scenario.
- PaulHoule 5y agoEscher or Kafka? So far as I can tell, 2FA in a low touch environment means it is a matter of when not if you will be locked out without recourse.
- egypturnash 5y agoEscher works in this case: 'Drawing Hands'. https://d279m997dpfwgl.cloudfront.net/wp/2018/02/0207_escher-02.jpg https://d279m997dpfwgl.cloudfront.net/wp/2018/02/0207_escher...
- deleted 5y ago[deleted]
- blibble 5y agoI had this exact same problem... I was logging in on the same IP address I've used for 10 years I only managed to solve it by digging out an old phone that was still signed into the Google account... if I had factory reset that then I suspect I would have lost it forever this experience is one of the many reasons I've dumped Google wherever possible
- anter 5y agoYep, have had that issue for over a year now, I am completely unable to access my old gmail account despite having the password, recovery email and everything else. Just says "you can’t sign in" and that's it: https://i.imgur.com/4YrElkJ.png https://i.imgur.com/4YrElkJ.png
- empressplay 5y agoTry using a VPN to log in from the location you last used the account
- shitloadofbooks 5y agoLogging in from a known VPN IP will likely flag the activity as even MORE suspicious from Google's AI's POV.
- empressplay 5y agoThat has not been my experience. I was able to recover two google accounts by using a VPN
- napsterbr 5y agoPerhaps a better alternative than VPN (given it may look suspicious) would be to spin up an $cloud instance at whatever location and using a SOCKS proxy. I used to do this back in the day to augment my Netflix selection.
- cheeze 5y agoThis is no better. All the big cloud providers have their CIDR ranges published
- megous 5y agoNot sure why you're downvoted. Setting up VPN on my home router and using that VPN on my next travel will be the first thing I'll do prepping for a vacation. Using VPN is a right solution. All the geo-IP nonsense is absolutely crazy, including these random login blocks and "security" checks. You also get UI reset to languages you don't understand, because no, websites can't use the language you set in your browser, they have to use some geo-IP nonsense to select a language (especially funny with IPv6). And there's no persistent switch if you use private mode, because they don't respect UA settings.
- davemtl 5y agoOnce again this shows that we're at the mercy of the giant AI machine. For fear of having my data locked into Google, I migrated to my own domain and e-mail hosting elsewhere. I'm still at the mercy of the hosting and domain registrar at that point, but at least they have phone numbers I can call to get support and talk to a human. Offline backups is a must at this point.
- rootusrootus 5y ago> at least they have phone numbers I can call to get support and talk to a human. This is important. I've decided to move all of the services I care about to a paid platform with properly paid support staff. This whole 'get it for free!' crap with the tech companies is just too much risk. I make more than enough money, I can afford a few bucks for the things that matter. Gmail is an awful choice for something so critical as your primary email account.
- gitowiec 5y agoSome similar thing happen to me. Gmail login page says that I need to acknowledge that me is me and it forces me to change password... I occasionally get this message on screen when I change countries with VPN. I need to use VPN different countries because this is required by my work (development of streaming services). I get so much annoyed. Recently I spent Christmas in Norway (not the country of my origin) and that happened again. I had to access Gmail to check in the flight so I was forced to change the password. This is ridiculous!
- ajdoingnothing 5y agoIf there is one Google service I'd happily pay 10 bucks a month for (given that they would then provide proper support), it'd be gmail.... It'd be a nightmare for any gmail user when suddenly their account is blocked for no particular reason. This post is reminding me to look for alternatives.
- EamonnMR 5y agoThey're trying to deter you from using Gmail anonymously/as a burner email.
- FabHK 5y agoI think that's it. They might consider three use cases: 1. normal usage multiple times a day, 2. grandma using it once a month, but always from the same device at the same location, 3. people using as an anonymous/burner account (likely from a clean/incognito browser session, maybe using a VPN, without phone number on file, etc.) With the current implementation, 1 and 2 still mostly works, and they don't care that they make it impossible/inconvenient for 3.
- 5ESS 5y agoTry to login from a device that you used previously to login to other different accounts that you touched from the same device that was used to login previously.
- 3np 5y agoHappened to my grandma, who have had the same address for over 10 years. Was quite the ordeal to have her change over to a new adress once we decided it was meaningless to hope to regain access.
- coldtea 5y agoThe faster we move from location/PINs sent to mobile, and other BS forms of 2FA the better...
- calltrak 5y ago
- throwhauser 5y agoI guess the takeaway here is that it might be better to de-google-ize yourself on your own initiative than to deal with having it done to you unexpectedly.
- kmetan 5y agoI have solved this couple of months ago: 1) dont try to login couple of weeks (this was recommended on multiple boards) 2) try again with the recovery email My problem was a) I didn't log in during the previous 12 months b) I moved to another country. Only when I connected via vpn to the country of my previous residence, I got in. Took me more then 4 months to figure this out...
- thaumasiotes 5y agoI ran into the same problem and complained on HN a while ago. In my case, I was able to access my email in an incognito tab, although that didn't seem to be a universal solution.
- einpoklum 5y agoImmediate solution to try: Use a mail client to access your mailbox with IMAP or POP3; GMail may be more tolerant that way. Long-term solution: Stop using Google. Why? Not just because of this type of shenanigans, but because Google spies on you: * It keeps a copy of all of your correspondence, even if you delete it. * (Rephrased) The US National Security Agency (NSA) has gotten access to much of your correspondence, by tapping links between Google's data center; it may still have such access today and Google's extent of collaboration with this is not known for certain (to me anyway). * It uses your correspondence and other information about you allow commercial companies to manipulate you with advertisement. (The NSA part was verified by Edward Snowden's revelations, several years back; see: https://www.washingtonpost.com/world/national-security/nsa-infiltrates-links-to-yahoo-google-data-centers-worldwide-snowden-documents-say/2013/10/30/e51d661e-4166-11e3-8b74-d89d714ca4dd_story.html https://www.washingtonpost.com/world/national-security/nsa-i... for example) Now, no third-party mail service is perfectly safe; but you should want one which is at least somewhat-safe, and that doesn't treat you unfairly. I won't make specific recommendations, but I've personally had decent experience with ProtonMail (Switzerland) and gmx.com (Germany).
- kccqzy 5y ago> It send the US National Security Agency (NSA) a copy of all of your correspondence Google did no such thing. What Snowden revealed was that the NSA knew at that time the SSL connections from a user to Google were terminated at the GFE, and all the traffic between Google data centers were in cleartext. That includes, for example, a request from an application to store some user data in a database or storage system, or the replication between data centers of user data for redundancy purposes. NSA then wiretapped these communication links. See this leaked NSA slide: https://commons.wikimedia.org/wiki/File:NSA_Muscular_Google_Cloud.jpg https://commons.wikimedia.org/wiki/File:NSA_Muscular_Google_...
- einpoklum 5y agoI stand corrected and have edited my answer.
- parhamn 5y agoThey also do this thing now where they block [1] smaller browsers (even ones using the latest version of chromium) under the guise of security. According to their docs they're fighting MITMs by generally disallowing any browser they can't identify (so the big few). If you're not on a whitelisted browser by Google, you can't log in (effectively, use) any of their properties. This feels very anti-competitive to me. Notably all the whitelisted browsers are either theirs (Chrome) or sell them their search traffic. I'm building a browser for research [2] and have to frequently find workarounds. I'm not quite sure who I'd contact to get on said whitelist either... [1] https://imgur.com/a/DASVkhl https://imgur.com/a/DASVkhl (here is the issue in the Vim browser and Min browser) [2] https://synth.app https://synth.app
- manish_gill 5y agoJust signed up. Your idea appeals to me. Hope I can take it for a spin soon!
- bpye 5y agoWow, that's awful. I wonder who's idea it was? Is it doing anything more than checking user agent (trivial to spoof), because if not that seems entirely hostile.
- parhamn 5y agoIt's not just the user-agent, it is definitely doing non-trivial fingerprinting (both linked projects also had UA mitigations before). We don't have an easy workaround (besides a sketchy cookie hack that took hours to reverse engineer) right now and have been trying to get in touch with them.
- ilrwbwrkhv 5y agoWhat did min browser have?
- klabb3 5y ago> it is definitely doing non-trivial fingerprinting Can confirm. To generalize and understand why, big corps have to deal with an insane amount of (often automated) abuse, so they build profiles using data collection to assess your risk level. Being in the wrong cohort (say unusual browser, small country, rare language, use a vpn etc) can affect your score. Basically it's these massive bayesian filters that output how suspicious some activity is. Whether you're signing in to Gmail, returning a product, buying something with a credit card or booking an Uber, some form of score is computed and then used to allow/deny/delay/verify. Obviously this is well established in the insurance and finance industries, but make no mistake, it happens everywhere. This approach is understandable from a business perspective, but imo deeply troubling for an open society. You don't have to squint much in order to see the similarities to social credit systems, EVEN if there is no grand totalitarian state-coordinated behind it. As usual, the first step is transparency so we can actually discuss these issues based on accurate data, but that's very difficult today. Usually fraud and abuse prevention is among the most secretive departments, they never share anything.
- tonymet 5y agoI feel your pain. You’ll probably have better luck logging in if you add a hardware token or 2fa. most android phones have a built in hardware token, or you can buy a yubikey or the tokens from google (often on sale for $5)
- tlhighbaugh 5y agotry user agent modification, it claims all this crap about wanting a device you signed in to before but in my humble experience using Linux + Firefox, all is fixed if I switch my user agent so it appears I am using Windows + Edge.
- tlhighbaugh 5y agothough this and the fact gmail manages to hide my important emails, I moved to using Zoho, which stays out of my way and plays nice with neomutt
- AshamedCaptain 5y agoOne day I logged in to my Amazon account from a different country. Mind you, I have 2FA/OTP enabled in my account, and I entered it correctly. They also made me click on a link they sent via email to "verify my login". A couple hours later my account was blocked due to "suspicious login(s)" (i.e. mine), and the order I placed cancelled. They had me wait 24h until I could contact someone at support that could unblock it. He told he was going to disable 2FA (?) and send me a code that I could use to change my password. The code was sent via SMS. They think that someone who has just my SIM card (or a clone, FFS) is more trustworthy than someone who has my password, 2FA token, and email address. These companies take user security as a joke, or as pure theater.
- xvector 5y agoThe amount of trust that providers put in phone numbers is absolutely insane.
- cassepipe 5y agoOr maybe do they really want your phone number? (Uninformed guess but isn't it valuable data?)
- yeetaccount4 5y agoI’ve always figured this was what they wanted. They probably tie it to your IMEI so they can track you everywhere online and in the real world. E: Seriously? This is a multi billion dollar industry. Oh no, Google would never do that…
- notreallyserio 5y agoMy phone number is probably the least valuable thing Amazon knows about me, I figure.
- novok 5y agoPhone numbers are basically super cookie identifiers unless you make a new phone number for each account and use different aliases & maybe addresses for them too. They all sell into centralized information systems and create profiles about you that are very detailed, which includes banking, income and credit info. So yes, the phone number is incredibly valuable, especially a place like amazon that shows different prices to different users and who's recommendation engine drives a lot of sales. Phone 2 factor is pretty much the only kind of 2 factor most people will accept, and for most people the phone number probably has better security than most people's emails, because most people reuse passwords, while with phones you had to do a special non-password effort for them.
- armchairhacker 5y agoThis is because most people use Gmail for basically all their online accounts: if you don't directly login to the site via Gmail, you can use your account to change your password. Imagine the damage which can be done if a malicious user breaks into someone's Gmail, if not your own, then the average person who uses the same password everywhere and trusts Gmail with everything. Not defending the practice at all. It shows we as a society and Google in particular need better security if they are flat-out locking people out of their Gmail accounts and others are still being compromised (I know they are). I honestly support Google forcing people to use recovery addresses and 2-factor authentication but I don't support them making the recovery authentication not work and providing literally no options for a legitimate user. I think the best you can do right now is complain on HN and Twitter and you'll probably get your account back. In the future, maybe if you have a YubiKey or stronger form of 2FA Google won't lock you out, because obviously if someone can authenticate with a YubiKey they are practically guaranteed to be the real person.
- tester756 5y agoSecurity comes at the cost of comfort You might not like it, but then you're free to disable this IIRC?
- mrslave 5y agoI stopped using it too. The email service isn't that great (minimizing email in general), Google can be a pain to use for reasons already mentioned, and at the time there was a small swing against surveillance capitalism. Anti-patterns in registration are annoying too. A recent example from Twitter: "sign up with phone or email" (defaults to phone); click email (colleague insists on only using phone for work); register with email only. 2 minutes later: "give us your phone number to unlock your account." Crazy.
- tpoacher 5y agoI had a similar issue with outlook when I went to visit my parents in Cyprus (normally I live in the UK) My main account gave me a similar message to yours; the only option was to approve this location via a link sent to my "nominated backup email". Which, also refused to let me in for exactly the same reason. *facepalm*
- qbasic_forever 5y agoTurn off any adblockers or other things that might be manipulating your browser sessions, cookies, etc.
- grammarnazzzi 5y agoYou get what you pay for. Microsoft hotmail is pretty much the same. Reailize that what you call "security" isn't there to protect you. It protects Google's interests. Google wants to minimize the risk of hackers compromising any google service; and if doing so might destroy your livelihood, well, that's a risk Google is willing to take.
- supermatou 5y agoYep, and it was even more aggravating. > have three gmail accounts > primary, name.surname@gmail.com > secondary, name.surname.purchases@gmail.com > tertiary, name.surname.work@gmail.com > secondary and tertiary have primary as a recovery address > log in/out once a week in 2nd and 3rd > last August, try to log into name.surname.work > "Password is incorrect" > WTH?! of course it's correct. > try several times, Google blocks me ("temporarily") > next day, try again, no dice. > OK, the hell with this: let's reset the password > "what's the last password you remember?" duh, the last and only password is the one I already gave you, you stupid machine. > "we need additional verification; input the recovery address" Finally! type my main address > mail from Google arrives pronto, code in it > type code in verification field > new mail from Google: "Thank you for verifying your mail address" [my primary one?!] Based on the information provided, we cannot ascertain that [tertiary account] belongs to you" This has been happening since. A few weeks ago, secondary account went down too, yielding the same error OP got. Note: a) I have been using the same IP and the same machine to log into those accounts for many years; there is no other device or location where I've signed in before! b) primary account has multiple (4) Yubikeys associated with it, so it should be clear I'm a real person and not a bot. I'm currently in panic mode: if my main account goes down, it will take a huge part of my life with it, from banks to government stuff.
- b112 5y agoSet up a real email provider, forward your mail from google to them, and transition over. If you want real identity security, reg your own domain, and move it with you.
- __d 5y agoThis 100%. It's the only way you can move your email between providers. Of course, it just shifts your risk to the domain registrar, so don't use someone too cheap. It's worth paying a decent fee for decent service here.
- fn-mote 5y ago> If you want real identity security, reg your own domain, and move it with you. I'm pretty confident that Gmail is more secure than the domain registrar if you're really attacked. At least do your research carefully on this one. Domains do get stolen. As always, consider your own threat model. But if you're a civilian? Wow, just hope you can walk away from the lockout.
- eyeball 5y agoturn on their advanced protection features and it gets even more fun
- dfdz 5y agoJust FYI there is a solution to this: enroll your gmail account in the advanced protection program https://landing.google.com/advancedprotection/ https://landing.google.com/advancedprotection/ When you login you are required to use a security key (like Yubi key) but it removes all the annoying emails and texts with codes, IP filtering, login AI, etc
- mianos 5y agoIf you use your phone as the security key and something goes wrong you are in exactly the same situation. Let alone with weird one where they talk to your phone using bluetooth as a security key. I have seen that one go very wrong so many times now.
- YPPH 5y agoThat's not a possible state to be in. Google won't let you set up Advanced Protection unless you configure a minimum of two security keys, one of which may be your phone's built-in key. https://support.google.com/accounts/answer/7539956 https://support.google.com/accounts/answer/7539956
- kart23 5y agothere needs to be some kind of law or regulation around this right? email has become as, if not more important as regular mail, and the government should be protecting access to it. try sending it to your senator and local representative. I think the FTC would also be interested in this. if google won’t even give you support for the issue, that should really be addressed by the government imo.
- throwawayay02 5y agoIn my country the state maintains an alternative to email, where you can receive messages from anything government related, plus any business that registers. It's opt-in only, you cannot receive spam or be subscribed to entities against your will, and of course if you lose access you can just go down to the nearest citizen's office and get it sorted. You can also pay bills through it. It is a nice solution but unfortunately everyone already has to have email accounts, so it becomes just yet another account to check, which is not attractive.
- akvadrako 5y agoThere is not need for a law. Just don't use google.
- kart23 5y agoIf someone wants to stop using gmail, it's horribly inconvenient to move to another service. You need to update your email with all your other accounts, which for most people is pretty much unfeasible. You can't take your @gmail.com address, which means switching email providers is extremely difficult. There should really be some consumer protection laws around email.
- commoner 5y agoEmail forwarding makes migrating away from Gmail substantially easier: https://support.google.com/mail/answer/10957 https://support.google.com/mail/answer/10957 With this, you don't have to update your email on all of your accounts at once. You can do it at your own pace. Consumer protection laws requiring data portability would still be welcome.
- jacekm 5y agoThings I can recommend in your situation, which helped me in the past, in no particular order: * log into other gmail account (with a long history) using Chrome without any addons, log out and then immediately try logging into the primary account (ideally google should ask you if you want to add another account) * log in from the same location. I once spent two years abroad, and could not log in to one of my accounts. I regained access only after returning to my home country * if you are working in an organization that owns an IP range, try logging in from work, i.e. do not use publicly available ISP. You'll get best results if you can combine two or more of these points. Unfortunately even following this advice you are not guaranteed to be successful... For the future reference, the only prevention that I know which works 100% times is using YubiKey for 2FA. 2FA with TOTP codes often helps unlocking the account, but I had cases where even the codes did not help.
- alecco 5y ago> using YubiKey for 2FA Today Google/Gmail suddenly logged me out and asked me for the hardware key, and I thought no problem as I have OTP with my Password Manager, but OTP didn't work. I had the key somewhere else. Luckily after insisting a bit Google gave me the option to use my mobile Gmail app to verify it's me (note it was not Google Authenticator, why did they made me install it?). All this hassle even though I've been on the same ISP/IP range and computer for weeks. No VPN or anything. On top of the multiple authentication options, I'm going to add a second hardware key in case I lose my main one and Google decides it's the only way to log in. Edit: the OTP option is not there anymore in my Google account 2-Step Verification, but it did ask for it and it failed.
- jacekm 5y agoI once had a situation where I didn't have access to my YubiKey but I had backup codes (not from the authenticator app but the 10 codes you are given when you set up 2FA for the first time). I could log in but I thought I'll remove the YubiKey from the account and set up TOTP (Authenticator) instead. It turns out you cannot do this using only backup codes, you have to have the key! So if you loose your key and run out of your 10 codes, you may loose the access to the account forever! It seems that the only way to prevent this is to have two YubiKeys added to the account...
- ammonammonammon 5y agoI find account security horribly bloated thanks to tools like Podesta and such lame password creators. If ppl would simply make good passwords this would not be an issue. Google, Amazon, Valve/Steam, blah blah blah… we almost don’t need passwords anymore.
- _tom_ 5y agoI lost a google account that I had a recovery number set on. Google used it, verified it, then said it wasn't enough, and there went an email account I had used for years. No way to recover.
- zoellner 5y agoeBay blocks my account for suspicious activity every time I post something. Completely unusable for occasional use
- upbeat_general 5y agoI had the same issue. I just gave up and came a while later with the same IP and eventually got through. It’s ridiculous that they both allow you to not setup 2FA and don’t let you in without whatever they deem required. I eventually started using 1Password for all my backup google accounts to setup TOTP making it just as convenient as without 2FA. It was still a pain to have to wait and go through the process though.
- atarian 5y agoI've seen this a lot with incognito mode too. I think Google just deals a large penalty for "clean" devices.
- WithinReason 5y agoThis is your daily reminder to Gmail users to set up automatic email forwarding to a secondary (free) address. I recommend ProtonMail, you can set emails to autodelete after X time so you never fill your quota.
- voisin 5y agoNearly every interaction I have had with Google in the last two years makes me think the company has devolved into warring factions that cannot communicate let alone coordinate for the betterment of their users. Do they not eat their own cooking, or how do they manage to make everything so dysfunctional?
- hotpotamus 5y agoPerhaps remote work doesn't lend itself to a well coordinated company?
- Havoc 5y agoGoogle has lost its way long before the pandemic
- sumedh 5y ago> has devolved into warring factions that cannot communicate Maybe they should come up with a new chat app that will fix the communication issues.
- deleted 5y ago[deleted]
- dynamohk 5y agoPassword reset functions for most providers often make 2FA hardware/software tokens useless. They fall back to email/sms to reset forgotten password/tokens. I guess it’s usability for majority over security that would lock out users.
- Avamander 5y agoIf TOTP or Webauth is offered at all, usually it's some garbage like SMS. Twitch, eBay and Amazon all three are really disgustingly pushy with it with some bullshit excuses.
- harshalizee 5y agoGoogle/Gmail is a nightmare to use for me as someone who travels overseas to visit family. Logging into Gmail from a different device is a harrowing experience. SMS 2FA doesn't work with many providers even with international roaming turned on. So you're dead in the water and face a potential account ban that can never be recovered. Years ago, I had my account suspended when I was implementing an Adsense integration into a site for no discernible reason. I have too many ancient financial institution's login tied up to my primary email. That was the last time I signed up for anything related to Google. At my workplace, I'm a strong advocate against the Google ecosystem. A few of us fought hard to keep our cloud systems away from Google and move to Azure. I've seen similar sentiments from quite a few devs in the last few years.
- pmlnr 5y agoFor critically important accounts, host it somewhere where you have the chance of talking to a human if things go boom. Google is not one of these.
- pixel_tracing 5y agoYou think that’s bad trying recovering a missing Microsoft outlook account. I have to wait on some verification and send my address previous addresses used, etc. Good luck.
- js2 5y agoEdit: I just got back in! I had to give a real phone # for the SMS step. It pretended to accept a Google Voice # but would never send a code and I just got stuck in the loop I describe below. I've now closed the account. Oh, the irony... Yup, I've got an old gmail account that Google won't let me into. First I get: "This device isn’t recognized. For your security, Google wants to make sure it’s really you." With options for "Confirm your recovery email" and "Get a verification code at <elided recovery email>." Regardless of which I choose, it then asks me for a phone # for an SMS code. So I give it one, just to get: "Unavailable because of too many failed attempts. Try again in a few hours." Except, "a few hours" is a lie. I last tried this weeks ago. I get a "Try another way" option which prompts me "Enter the last password you remember using with this Google Account." at which point I'm at a dead end because this account only ever had one password. The best part is that shortly after going through this exercise I get an email to the recovery address: "Sign-in attempt was blocked. Someone just used your password to try to sign in to your account. Google blocked them, but you should check what happened." With a "Check Activity" button that takes me right back to the Google sign page... Buttle? Tuttle? The irony in all of this is that I'd forgotten about the account until Google sent an "new terms of service" email to the recovery email address and decided I wanted to close the account. But I can't login to do so. Anyway, I switched my primary email away to Fastmail years ago and I'm still happy with that decision.
- kingcharles 5y agoDid you have a 27B/6? https://www.youtube.com/watch?v=CGeT5cutXgU https://www.youtube.com/watch?v=CGeT5cutXgU
- Minor49er 5y agoI have an account that I frequently sign into in an incognito session. Every time I do, Google emails the same account saying that it doesn't recognize the device. I've tried requesting that it remembers the device, but despite the browser and IP address staying the same, it doesn't seem to matter. Though it also appears that I can ignore these warnings entirely. The biggest issue that I have is that I have an email account through my web hosting provider that isn't connected to Google. If I email anyone with a Gmail address, it gets rejected for being potential spam, despite not having any links or anything. Even if I respond to someone writing from a Gmail address, Google will reject it, saying that it was unsolicited since I was the one initiating the conversation, which is simply ridiculous. I usually end up logging into a separate Gmail account just to communicate with those users.
- amelius 5y agoPerhaps you'd have more luck using a Firefox Container instead.
- C4K3 5y agoOne site I've found particularly annoying in this regard is ebay. I'll log in, enter a 2FA code (both SMS and email), do whatever I need to, and then 30 minutes later I'll get an email saying my password has been reset because of suspicious activity. ("your eBay account has been secured because your login information may have been used without your permission") This has happened several times now. At least they haven't canceled any of my orders or anything.
- deleted 5y ago[deleted]
- Avamander 5y agoeBay does the same shit, but they force a password reset on you instead. Have to reset my password basically once a month because their heuristics are absolutely dogshit.
- LegitShady 5y agohave old gmail account no longer have associated phone number Do have backup email (primary email). Do have password. Google doesn't care. Won't let me log in, won't send an email to the primary account for recovery, etc. I've written it off. Essentially if I'm not paying someone for it, they don't care.
- deleted 5y ago[deleted]
- ashtonkem 5y agoIt keeps locking out my printer for using LDAP. It's extremely annoying to go and re-check the "yes, allow 'insecure' access" every N months. I complain a lot in the box, but obviously nobody is reading them.
- riidom 5y agoI had a similar case, in one of my (lesser) gmail accounts. I took that as final warning and since then started to move away from google mail. Currently, I use a posteo mail, which costs me 1€ (I believe) per month, for the important stuff. Mails which come as part of my webhosting package for most of the other stuff. And a free adress (web.de) as experiment, but it didn't turn out too bad so I keep it for unimportant stuff They just send ads as mail once a week. Calling this "mildly annoying" is exaggerated already. Yea, so the takeaway (imo) is, leave the sinking ship before it sinks you. The process may take weeks or months if you proceed it relaxed (that's how I did it), so start before one of your important addresses gets hit.
- pkulak 5y agoIt’s this kind of thing that has had me moving most everything off Google over the last 6 months. It’s just not safe for me to have 20 years of photos, emails and documents in the hands of a company that may cut me loose at any moment. After decades of slowly moving my life to “the cloud”, I bought a Synology nas, and now all my stuff lives in my own house (though backed up externally, of course).
- frozenlettuce 5y agoI have this exact issue since I changed my phone number and forgot to update it in all my Google accounts. Now I can't access an account that has some adsense funds. Lesson learned: don't trust a company that doesn't have customer support.
- ksec 5y agoLooking at all the Google, Amazon, PayPal and comments on many others, security UX is simply an unsolved problem. I am wondering if YubiKey would have the same problem? Edit: Looks like not.
- dheera 5y agoGoogle has a good Yubikey implementation (they allow multiple keys), Amazon and PayPal are 100% crap implementations. I had a website with probably 10K monthly active users go down for a week because I was travelling with a different Yubikey and AWS only allows 1 Yubikey to be registered. I've also had PayPal payments have to be delayed until I got back home because of the same reason, they only allow 1 Yubikey. Horrible quality products.
- IvanK_net 5y agoI think we, "people", pushed companies to do this. There are billions of people creating various accounts. Hundreds of thousands of them had a weak password, or told their password to someone, etc, and their data leaked. There were so many news about "data leaks" and "security issues" in the past 20 years, and each time, a company was blamed, never a user. We even made laws, where letting people log in with only a password can be illegal.
- Gwarzo 5y agoI actually don't mind this take - it's no doubt the security rules for google services are a bit over the top, but it's not like they don't have good reason to do it; or even to be anti-user.
- novok 5y agoThis is why you want your email to be your own domain, so even if you still use gmail, you can recover from that.
- nikolay 5y agoWe'll always be hostages of Google while we keep using their services.
- mikotodomo 5y agoThey have calculated that overall, a non-negligible amount of users will be hacked unless they have their system the way it is. Sure some accounts will get locked out, but overall it's a net benefit. There are hidden variables.
- lucb1e 5y agoBased on what I see while consulting, I feel like more strange company behavior is attributed to cleverness than the real amount of stupidity/randomness that goes on. Here, too, there are so many variables and unknowns, this is not a calculable number. And even if they could, I am not sure they necessarily would. Bigcorps are not infallible and do not get everything correct with meticulous calculations on boatloads of data, much as they might try to give that impression.
- mikotodomo 5y agoThe variables are hidden because the system would be insecure if they were known.
- empressplay 5y agoIf you've moved to a different country / region, use a VPN to access the account from the old location, then after that point the device will be okay
- neogodless 5y agoMy 87 year old grandma's computer wouldn't boot. We set her up on a new laptop. But we couldn't remember her Gmail password. We never recovered her account, including any photos backed up to Google Photos.
- zozbot234 5y agoYou should be able to image her hard disk, and probably boot it up in a VM. Windows activation might complain in that case, but her data will be there.
- cesarb 5y ago> You should be able to image her hard disk, and probably boot it up in a VM. Is that still an option? I haven't used Windows for a long time, but I believe Microsoft has been pushing towards enabling BitLocker by default for everyone. If you don't have the BitLocker recovery key, or access to the user's Microsoft cloud account (which AFAIK has a copy of the BitLocker recovery key), the only way to decrypt the hard disk is to boot the system the normal way (with SecureBoot enabled even), since the key is held on the TPM.
- zozbot234 5y agoIf you have BitLocker enabled, you'll know about it. It's not the kind of thing that happens by accident.
- neogodless 5y agoYup there's a few things to try yet when I can get the hard drive from my family member. But I'm not optimistic about the Google account either way!
- dmitrygr 5y agoYour only option is a helpful googler who can fill out the internal "help recover an account" form. You this sucks. But having accounts stolen sucks too. I think Google is between a rock and a hard place here. But anyways, sucks. -Xoogler
- alyandon 5y agoI had an ancient Google account that I hadn't logged into in forever that put me into a similar recovery loop. I had the correct password for the account and it said I was logging in from a new device and asked for my recovery email. It sent a code to my recovery email account and I entered the code into the page. So Google knew the following: 1) I have the correct password to the Google account 2) The recovery email address is valid and the code I entered matched Despite that, after entering the code I received an error message stating essentially "Thank you for providing the correct code however we are still unable to verify your account". I then reached out to a contact within Google and they escalated the issue and the account access was restored for about a week or so before it went back into the same recovery loop. I gave up after that.
- Havoc 5y agoI’ve also noticed that google like logging me out regularly if I’m using more filtering tools (think pihole etc). The ridiculous part is I’m on a static IP…google damn well knows it’s me
- whoknew1122 5y agoAs a security professional, this is something we deal with daily. Security is too lax? Why didn't you protect my data. Security is too strong? I can't easily access my data! Can someone show me the Goldilocks zone for internet security? It's a moving target.
- pkulak 5y agoGoldilocks for me is not allowing brute force password attacks and trusting me to create a non-worthless password.
- foxfluff 5y agoHave you considered that these are different groups of people talking? I'd like to take responsibility for my part by not reusing passwords, not using weak passwords, not using my passwords on computers that I can't trust (other people's PCs, public computers, etc.), etcetra. There's not a whole lot on my end other than physical security and the possibility of malware (not very likely on my systems which generally rely on a small set of linux & bsd packages from distros' official repos). For critical stuff I do some kind of 2fa or OTP too. Which is to say, it is almost possible for an attacker to gain my credentials. Now if you do your part, your company won't leak my password either. You won't allow bots to bruteforce trillions of hashes per second. You don't allow your infra or certificates to be compromised. Don't mail me my password. Don't let some rando in if they call or send an email claiming to be me (unless you're a bank and that someone shows up with a valid government issued id plus passes a basic background check). And so on. If we each do our part, the system is secure. There is no need for you to block access to my account when valid credentials are presented. The only time I've had a breach that was on me when I was a kid and ran a fucking runescape autominer. Every other time, it's been on the company; either they get breached, or their "security" fails and blocks me. I don't consider that "too strong" security. I consider that weak security, because the job of security is to ensure secure access, and with no access, security has failed its job. And if you permanently lock someone out, as Google has done many times, it's equivalent to putting the user's data through the shredder. That's incredibly bad security; a complete failure to protect the data.
- enobrev 5y agoThis reminds me of a story from a couple years ago (pre-covid). I dropped my brand new phone before my case arrived in the mail and cracked the screen. We were on our way to the movie theater and so I decided to drop off my phone to get it fixed before the movie and then we would pick it up on the way home. Perfect plan! Except I bought the tickets through an app and now I didn't have that app. Nor did I know the password, because I use a pw manager. The person at the booth said I could use the confirmation email, so I tried on my wife's phone. It wouldn't let me log in to gmail from her phone no matter what I tried. Different browsers, desktop mode, etc. There was no getting in. We were about to miss the start of the movie so I just went ahead and bought two more tickets and got a refund later.
- alanh 5y agoYes, this happened to me with a throwaway gmail address I once had. Correct name and (strong) password, BS about a different device. I never regained access. Luckily nothing of real value was lost. My primary email account is on Fastmail these days, and I like them.
- whitesilhouette 5y agoOnly solution that works for me is to use my 8 digit backup codes. That works everytime.
- alexnewman 5y agoGood news , CloudFlare does email routing
- tadzikpk 5y agoUse Che browser to mimic your usual device… https://chebrowser.site/ https://chebrowser.site/
- alanh 5y agoReminder: Google paid for an ad campaign with this gist: A father creates a Gmail account for his daughter when she is born, and sends her important photos and mementos as she grows up. Sweet. Reality: At least one person tried this in real life, and the child's account was automatically deleted without recourse. https://tech.slashdot.org/story/11/12/18/2046221/why-google-is-disabling-kids-gmail-accounts https://tech.slashdot.org/story/11/12/18/2046221/why-google-...
- snowwrestler 5y agoYou can do this with a regular Gmail account. The kid just can’t log into it until they are 13 or older. Google also now offers child Google accounts for kids under 13, which are limited and tied to a parent’s account through an app called Family Link. This is how you can set up a Chromebook for a kid, for example. This limit of age 13 is not arbitrary by Google; it’s their way of complying with a U.S. federal law called COPPA.
- kvhdude 5y agoI had a different problem. On my wife's account she started receiving someone else's emails. Initially we suspected that her email was wrongly(typo) used in registration at various sites. But increasingly we noticed that the conversations in the mails were ongoing, implying continued usage of her address. We suspected her email was hacked and changed password, that didnt help. Eventually she had to abandon that email. The problem with free mail service is that the support you get is what you pay for.
- Madmallard 5y agoI dont recall the password of my old gmail account and I listed my current gmail account as the recovery email, and they still cannot recover the account for me. It makes absolutely zero sense. It just seems like entirely lazy.
- lucb1e 5y agoI had this in ~2014 at an event. It literally would not let me log in no matter what. This did reinforce that running my own email server was a good idea. Like, what are you going to do if it actually is important? Call google support? I'd be surprised if they have a helpdesk with humans nowadays, let alone to fix some free account at 1am in the morning. Or even if you get to talk to a human, what are they going to do? Disable a security measure because a kind voice asks them to? Google thought my IP address was in Russia (I was in Germany) and I guess that makes it suspicious? (Feels a bit odd that entire countries are basically banned. Not as if criminals can't use a VPS or VPN, it's security theater and seems insulting to everyone living there: they're all considered guilty until proven innocent.) I think I later checked and saw that there were no other active login sessions, so it knew that I could not possibly have done as it suggested. (Or maybe that was another instance of this problem, not sure anymore after 5+ years. I never forgot the lesson though...) The reason for logging in wasn't time-sensitive so I let it go for the four days of the event. A related problem is that I have to clean up my inbox after logging into various services. Twitter was one of the first and I apparently got annoyed enough that I stopped using it subconsciously (I only later noticed that I had stopped checking Twitter and figured that the annoyance factor must be the reason). Like yeah you don't recognize my device, I don't want your "tweet" buttons across the web to track me so of course this appears as a new login device. What would be more suspicious is a login from a known device to this account, if the machine learning functions correctly...
- gruez 5y ago>Google thought the IP address was in Russia and I guess that makes it suspicious? (Feels a bit odd that entire countries are basically banned. I'm not sure why you immediately jumped to the conclusion that google is blocking entire countries. It seems fairly reasonable to block signins from russia if the account was created and has a history of signing in from another far-away country (eg. US). >Not as if criminals can't use a VPS or VPN, it's security theater and seems insulting to everyone living there: they're all considered guilty until proven innocent.) Google is probably doing more checks than looking at the country code from a geoip lookup. VPN/VPS IPs are easily distinguished from typical IPs (eg. residential internet and/or mobile internet).
- zeroimpl 5y agoSame sort of problem. I have an account like that which was giving these messages and after trying a lot of things over few weeks I gave up. Some long time later (year+) I retried and got in. I attempted to change the security settings, but it wouldn’t let me. Some long time later again, I’m now locked out again. This whole thing is ridiculous. I know the password, and have access to the account to which it forwards all emails. It should be obvious that their is no IP address which regularly uses this account, and that they are clearly locking out the account owner for no good reason.
- bananamerica 5y agoGoogle has some kind of backup code that you can get. It says so here https://support.google.com/accounts/answer/1187538?hl=en&co=GENIE.Platform%3DDesktop https://support.google.com/accounts/answer/1187538?hl=en&co=... Does it actually work?
- dTal 5y agoHit this over XMas. Dad got a new fire stick. Wanted to use the YouTube app. Wanted to sign in to YouTube for channel subscriptions. Had a GMail account he'd not used in years. Tried to recover it with the whole send-a-code-to-secondary-email rigmarole. Google went to the trouble of sending a code, but upon successful entry decided that it just wasn't good enough. Maddening. Gmail account gone forever. Can't sign up for a new one because "phone number used too many times". Fuck me I guess, guess we'll have to use one of the unofficial YouTube apps that do client-side subscriptions and incidentally block ads.
- throwaw123x3 5y ago> "phone number used too many times" Reminds me of that time we did a project for google. They couldn't give us accounts which was required to do the job for them, too much hassle even for them internally. We bought a dozen phone numbers and invoiced them instead. (There is some humor in invoicing Google for circumventing a Google security system.) Each phone number is good for a handful of accounts per ~2 years iirc. This is in a country with ID verification for a new phone number (no, it's not russia/iran/china... it is germany). The person behind the counter was not happy when I showed up to a busy post office with a stack of ID verification requests. (I couldn't have gone at a quiet time: they scale employees and I queue for 15-20 minutes every time also for a 20-second package pickup, no matter which day of the week, which time of day, or which city I go in.)
- Kelamir 5y agoI recommend NewPipe for watching YouTube on phone. Best of its kind, free and open-source. https://newpipe.net/ https://newpipe.net/
- Guest19023892 5y agoI had this happen as well about 8 years ago. My Gmail account one day just said it couldn't log me in, even though my password was correct, and I was logging in from the same home address and browser as always. It said I needed to complete the security question to access my account. I didn't know the answer because I just set random letters and numbers for the security answer when configuring the account recovery, because I was confident in my password and backup system. Since I couldn't answer that question, and because Google has no support, I could never access that account again while knowing the password. Fortunately this was a secondary email address, and my primary email was on my own domain.
- missingcolours 5y agoGlad to see others are also frustrated with Google's extremely excessive "security" gimmicks. The one that I run into sometimes: in order to do "Find My Phone" for my wife's phone, I try to sign in as her. In order to 2FA authenticate, I need to press yes on her (lost) phone, or answer a phone call or text on her (lost) phone. What exactly is the point of a find phone feature that requires you to have the phone? Apple doesn't have this issue BTW; they have some 2FA stuff but Find My iPhone is excluded so you can use it if your phone is missing.
- mekoka 5y agoThose of us who move around quite often can attest to how frustrating the security of online services has gotten. It can get even worse if you provide a phone number for "added security" and find yourself in a different country with a different phone. I've witnessed a few fellow travelers getting locked out of accounts because they couldn't access the SMS sent to their home phone number and the app was ignoring the code sent via email. Yahoo, Amazon, Gmail. I've even seen someone unable to use their Airbnb account for this very reason, which is odd considering that the service caters to travelers (that was 6 years ago, so maybe things have changed). If you travel and change phone numbers often, avoid giving it for security if you can.
- lucb1e 5y agoI know the pain of the internet with borders. Paypal phone support literally told me to close my Dutch account and open a new German account so that I can use paypal in Germany. If you can login to paypal from abroad, that is a bug according to them, you're not supposed to be able to login from abroad (like when on holiday) and need to make a new account instead. (I currently start a VPN into NL every time I need to use paypal; one more reason to avoid them.) In their defense: at least paypal has phone support. Try that with a gmail account.
- vault 5y agoPayPal is just as bad. After I moved country, I forgot to log in into my old PayPal account for months, and I've never been able to log in again, even having the right password, the same phone number, everything.
- moralestapia 5y agoGoogle is absolute trash now compared to what it was. Most accurate search engine is now almost useless even for VERBATIM queries; queries that took milliseconds earlier (they even built a product around that, Google Instant), now take 2-3 seconds on average. Best email service, now feels clunky and slow plus the spam algorithm not only stopped working, but is now working backwards. Everything just worked and it was simple to grasp and to work with, now we have issues everywhere with their draconian 2FA among other "wise" decisions in the name of "security". All this while on Android, basic stuff like calling 911 so you don't die is not possible because of all the other "features" they keep adding to the platform, see: https://news.ycombinator.com/item?id=29492884 https://news.ycombinator.com/item?id=29492884
- slig 5y ago>Best email service, now feels clunky and slow plus the spam algorithm not only stopped working, but is now working backwards. That's annoying, and they don't even care anymore. Now I have to check my spam folder multiple times a day. A lot of legitimate email is going to spam and vice-versa.
- rkalla 5y agoI understand how you end up here - after a decade or more of micro-optimizations down a pit of the newest/most advanced scam and take over techniques... but at some point you need to sit back, zoom out and look at collectively what you've created and see if you are catching a bit too much in the net. I feel like Risk underwriting at Finance/FinTech companies goes through something similar... the list of rules only ever gets longer/gets added to.. I don't know that anyoen rewinds the clock every 5 years and starts from a clean slate to build out a new model.
- rswail 5y agoLately I've noticed that Google wants me to "open the youtube app on your phone" even though I've configured 2FA. This is a work account, I have no interest in associating it to the youtube app on my phone. My own email is with fastmail. They do what they do particularly well and are worth it.
- itchyjunk 5y agoThis happened to me. I had half given up on my account since I didn't have a phone attached. Knowing my password and recovery email doesn't help. I emailed to some support email for google partnered people. I am not sure who I emailed but they responded that I was emailing the wrong person but they checked the status and it looked all good. I tried longing and it worked without any issue. Edit: I was super happy to see a human response at that point and was very hopeful when I tried to sign in again.
- hsbauauvhabzb 5y agoI regularly get security notifications for an account I’ve since lost the password to, the notifications go to my primary email, and this means a malicious actor has my password. I can’t login via account recovery, using my backup email, for the same reasons as described so I’m at a stalemate with some random malicious hacker and have no way of solving the issue, and no idea what’s actually in the account. Fuck you google.
- deleted 5y ago[deleted]
- izzytcp 5y agoIf you have a friend in the Feds, call them they give access to Feds immediately, zero requirements. Security is gone, poof. (sarcasm)
- windex 5y agoI am going to try and avoid google from here on out. Far too much instability around the google services I use the most. It's unfortunate that I've used the gmail id for just about everything including taxes. I feel google is entering a phase where it will look at all of its services for cutting down on "freebies."
- eddieh 5y agoYup, I am effectively locked out of a few email addresses I rarely used as well. I haven’t found a solution. I just moved everything important off of Google and would never trust them with anything at all—ever.
- _7kjo 5y agoI’m in the same situation and have an account that I have a password to, but cannot login to for the same reasons. Google is one of the companies I’d trust the least for anything critical.
- jscheel 5y agoNot, Google, but I'm having sort of the same problem with Facebook. My church has a Facebook account that we used to set up our public page years ago. We assigned editors to the page, then promptly never used that account again. Fast forward to this year, and I need to add a new editor, which only the page admin can do. I reset the password on the church's facebook account (it was lost years ago), but when I log in, it says it doesn't recognize my location and it needs me to get codes from a list of trusted contacts (a list that I'm fairly certain we never set up). When any of those trusted contacts go to the page it lists, Facebook tells them they aren't trusted contacts. I have tried to get Facebook to respond to me in every single possible way. I have gone through all of their help pages, talked to their bot until it said it would forward my message to a human that could help, sent emails to every address I could find, reported the page and account on every form I could, hit up Meta on other social media, and even reached out to Oculus support and offered to buy a headset if I needed one for them to be able to help me get access back to the account. The only response I've gotten is from Oculus telling me they can't do anything. That's it. No other responses at all. I swear it would be easier to answer one of the 37 recruiters that have reached out to me, interviewed for a position, gotten hired, and then fixed it myself.
- Aeolun 5y agoCan you find a facebook engineer on LinkedIn and send them a InMail? Only costs you one month of linkedin plus, or whatever it is called.
- sha256sum 5y agoI understand you are saying this in good faith, but honestly this is bullshit. Is the only way to get a solution to use LinkedIn inmail to solve a login crisis? There are plenty of FB engineers on this site alone. Are you all feeling okay with the work you’ve done?
- nikanj 5y agoThere’s plenty of ways: 1) Get your story on HN front page 2) Get a job at FB, fix issue yourself 3) Install Tinder, drive near FB offices, set search radius to minimum. Try to convince your matches to fix things 4) Buy a 0-day from the dark web, hack into FB and reset the password 5) Become incredibly wealthy, acrue enough FB stock to get a board seat, complain to the CEO
- WheatM 5y ago
- gkanai 5y agoI have my own domain and use email with that domain. I have a gmail account but only use it for mailing lists, ecommerce orders, etc. Relying on Gmail for everything is a bad, bad idea.
- cmurf 5y agoEvery week my google workspace accounts kick me out on my laptop, and I have to log back in with a password. This never happens on my Android phone with those accounts. And also not on the laptop with my regular gmail account.
- eyelidlessness 5y agoAnother fun one (not Gmail but Google property): ReCAPTCHA will validate and re-CAPTCHA you infinitely if you’re using Private Relay. They could just, like, store a cookie… they already have (assume) permission to do it. But just green checkmark > same question forever.
- ranuzz 5y agoHappened to me too. Gmail asked for a valid phone number for verification though and after that it worked.
- jerieljan 5y agoI've had this problem too. In terms of security, it's great, but it's terrible when you're going back to old, dormant accounts and have lost trusted devices. Thankfully, it's not a problem if you've set recovery emails and 2FA options, but it is easy to forget if the accounts are set up for someone else who isn't checking often (like family members who only use their accounts rarely) It really takes months for the lockout to clear up, and it sucks when it happens.
- zdw 5y agoThe most insane thing is is not being able to sign in with the kind of 2FA you want until after you've signed in with a phone number. This also affects paid Google Workspace accounts, which has a setting on GW to disable phone-based auth... So you're stuck. you can't have people sign into 2FA until they do it via phone... and they can't do it via phone by security policy... Just nuts.
- dimsum4 5y agoI have a 80+ old father. The security controls Google has put in place, I much appreciate them because he keeps a fairly simple password (but not one that is susceptible to dictionary attacks) and he cannot remember multiple passwords. I have tried using a password manager for him but he finds them too complicated. While I understand the pain this causes, any changes should accommodate the security and convenience of the older demographic.
- YeBanKo 5y agoArguable email addresses now are more important, that phone numbers. Mobile carriers are legally required to allow you to port numbers. We need a legal framework that allows to have inalienable email addresses.
- GuB-42 5y agoOr government issued email addresses tied to your identity, either as a citizen or as a registered company. Due to the decentralized nature of email, you can't have inalienable email addresses except within a domain. But you can register your own domain, and then, it is tied to your real identity and you can transfer it between registrars, which may be closer to what you had in mind. Most registrars provide an email relay, so that's probably the best you can get.
- YeBanKo 5y agoTo register a domain, you need an email. Phone numbers are as decentralized as email addresses. Obviously the current scheme is not gonna work and there has to be some sort of centralization. I don’t think email service issued by the government is the best way, but a dedicated domain with email relay that get an address at and then can you an email provider of your choosing.
- maccolgan 5y agoWe have one, it's called the DNS, IP and SMTP.
- joelbondurant1 5y ago
- Frost1x 5y agoFrom my experience, as a non-Apple user, they are the absolute worst. I bought a family member an iPad for Christmas. They had an Apple account associated with their iPhone. They forgot their password. No big deal, I'll just reset their password. Ha! We have to wait 24 hours after wrestling through the page, I leave my holiday visit in 36 hours, that's fine we have time I say to myself. A little odd but whatever, the account itself has no payment or important data associated with it really. 24 hours pass and the recovery page then suggests 14 days for recovery. What?!?! Why!?! (I mean, I get why, sort of, but I've done highly secure work that has less/shorter security processes than a consumer phone account). Apple says there's nothing they can do. That's fine, well just create a new email and account for them I say to myself for their iPad annoying and yet another account for them to remember, lose the password, and deal with but whatever. Ok new email, new Apple account, sign in and perfect. Now I just need to disassociate the phone with the account its locked out of and switch it to the new Apple account to make syncing things a bit easier between devices. Wait, I can't do this until I recover the account to sign in to then log out of in the device. Wow. Again, I understand the security model here, but wow, a consumer device? Insanity.
- Gigachad 5y agoThe problem is the Apple ID is heavily tied in to their anti theft features. So you just cant reset a device without the password. And people do not understand the gravity of this situation, someone at the Apple store really should be hammering it in that you must not ever lose your Apple ID password.
- steelframe 5y agoOnce upon a time I worked at Google. I returned to Austin to visit old friends and took the opportunity to visit the Google office there. The Googlers sitting around me were primarily corporate sales. They weren't getting any corporate sales calls at all as far as I could tell, but there was one extremely irate user who was locked out of their GMail account and was repeatedly calling them because they were the only human beings at Google the user was able to get in touch with, via something like "Press 3 for Corporate Sales." Of course these poor Google corporate sales people had absolutely no way to help this user even if they wanted to. Google literally did not have any GMail account phone support (at least at the time). I could hear the poor guy screaming through their headsets about how he paid Google something for some service and was entitled to phone support and he demanded someone help him, but they just kept saying, "This is corporate sales. We do not offer consumer account support. If you want support, please visit the Google Support Forums at www dot..." After they hung up on him 3 or 4 times, eventually a manager got on the phone and told him (between his screams), "Look, you're not getting any phone support because it doesn't exist. There's nowhere for us to transfer you. There's nobody who can call you back about this. Your only option is to search the forums for an answer to your problem. I am going to terminate this call now. Sir, I'm going to terminate this call. No, we can't help you. Nobody at Google can help you. I am terminating this call now. We asked you to stop calling this number. Do not call us again. <click>" I'd frequently tell my co-workers, "If you're not paying for it, you're the product." That experience underscored that notion for me.
- vbezhenar 5y agoI submitted security bug to Chrome. It was not very serious or urgent. Somebody looked at it in the first hour, in the first day it was analyzed and in the first week it was resolved. I was kind of surprised, because I was sure that public feedback from nobody is going to be put in a very long queue.
- eschulz 5y agoWas the screaming guy no paying for some service?
- 5y ago
- kadenwolff 5y agoI had this happen recently as well, have not found a solution
- aimor 5y agoYears ago, but just after Google purchased YouTube, I forgot my YouTube password so they emailed it to me in plaintext. Maybe 10 years ago I experienced forgotten Gmail password hell when a family member forgot their password and was never able to recover the account. Can't wait to see what the process is like another 10 years from now.
- octoberfranklin 5y agoFor over a decade I refused to give Google a phone number. Eventually they locked me out and demanded that I verify my account via SMS using a landline telephone number I hadn't had access to in over 8 years. Obviously since this was a landline, I could not possibly have given them this phone number for verification purposes and forgotten that I had done so. Evidently they scraped the phone number out of my email; I'd had PacBell e-bills emailed to that gmail address. Google is unreliable.
- anonymousiam 5y agoFacebook is the same way. If you don't have their cookies, but know your account name and have the recovery email, you still cannot log in after resetting your password unless you are stupid enough to send them a copy of your photo ID.
- nocommandline 5y agoI just had this experience yesterday! I entered the correct password, the right recovery email, even asked for a code to be sent to the recovery email address and entered it but Google still didn’t allow me log in. I had the same experience last year with the gmail account I created for my app. I travelled and Google didn’t allow me login from my laptop (cos I was in a different country). Entered the code from my recovery account and still no show. In both instances it asked for a phone number to send me a code. If it refused to accept the code from my recovery email, why would the one from a text message be different. Besides, I didn’t want to provide my phone number to gmail
- zuccs 5y agoI actually found the solution to this last time I had it. I get it all the time on legacy G Suite accounts that are still hanging around that I never log in to. I think it's this link: https://accounts.google.com/signin/recovery https://accounts.google.com/signin/recovery (don't go through the usual forgot email/password process on the login page or you get that stupid AI loop). I think it helps to use Google Chrome too.
- ryguytilidie 5y agoNot exactly what the OP is talking about, but I do consulting and have ~5 gmail accounts. My FAVORITE feature ever is: "huh. You just woke up on a Tuesday and need to get to work? Well, we've logged you out of all your accounts and need you to log in again." The worst.
- notreallyserio 5y ago"We have detected unusual activity on your account --Nothing has changed in the last 7 days. Please sign in again."
- kasi_hasi 5y agoThe solution to these kinds of problems is obvious: Stop using any Google service. No more Gmail, Google Cloud, Google Docs, Google Drive, ... there are many alternatives. I've pretty much completely degoogled my live and don't miss anything.
- IronWolve 5y agoGoogle security allows you to use a titan key, but then still ignores it if you use an android phone, not the best security, since phones can get sim jacked. (common way to get your ecoins hacked, take over your phone.) Defeats the purpose of a titan key and 2fa enabled. There is no option to turn off android auth confirmation popups, so you have to de-activate all signed in google phones, and remove google account on your cell for more security and stop trolls from spamming you, if your phone number is public. People been asking google for years to fix this major fubar. Google auth is designed by idiots, to be as easy as possible, but bad actors can abuse.
- kome 5y agoI have/had the same experience with Dropbox.
- osrec 5y agoWhy the heck is running a your own email server so complex?! I run my own email servers, as does my company, and they can be an absolute pain at times. Once you've got everything settled, they're okay, but still, they're unnecessarily fiddly things to get working. It should be easier, much much easier. Then we can all stop relying on external providers for substandard email services.
- maccolgan 5y agoIt's pretty simple if you use Docker and the mailserver images.
- throwawayboise 5y agoPretty sure if you have 2FA (Google Authenticator) set up this will never happen.
- Groxx 5y agoYep. They're getting aggressive with 2FA too. More ways to lock you out of your account in opaque, unpredictable ways with no support whatsoever. I'm very glad that I've already started moving my accounts off.
- greatgib 5y agoWhat piss me off the most with Gmail and google things like meet, is that if you are on Android, there is no way to login in a single app: Gmail, meet or even a third party email app without associating your Google account to the whole phone. This is really annoying. Sometimes I have to join corporate meeting from my personal email account on my personal phone, because if I would like to login with my pro one, all my personal phone will be associated and controllable by the company.
- joshuamorton 5y agoFWIW android supports Work profiles for exactly this purpose (though your company may not allow them). So for example I have my work and personal accounts on my phone, and my employer (Google in this case) can manage my work profile, up to and including erasing data on it, but can't do anything to my personal accounts.
- greatgib 5y agoStill, you will have to associate all your phone with this account to use a single app. Like search and all. That would not make sense if android was not tied to Google.
- russelg 5y agoYou can generate an app password then use gmail through IMAP using that password. (google it ;)
- greatgib 5y agoNope, this is the theory but in Android you will not be allowed to use anything else because even with IMAP you will need to go through oauth some times. Also, Google is regularly messing with the IMAP support. Like blocking their own server IPs as suspicious...
- ck2 5y agobtw if it helps, by "location" they mean the same ISP you used to create the account or last successfully used it old accounts without a valid phone number attached to get a SMS code are pretty much screwed if you change ISPs
- ranger_danger 5y agoI've lost several paying business accounts to this problem because I never log in except when a credit card expires and then I need to update it with a new one. By that point I've moved or changed computers or ISPs or something and there's no way to 'identify' me anymore.
- gxs 5y agoI realize I am a million years late to the party, but this is a good time to remind everyone to turn this “feature” off. It’s buried deep in settings but it can be disabled. The first time this happened to me I had to talk to an old employer to let me use my old laptop and sure enough it worked. I was very lucky. I hate google at this point - or rather how big these trillion dollar tech companies are getting. Would love a viable email alternative, but fast mail isn’t it.
- tootahe45 5y agoHave a similar problem here, I logged into my google account on a mobile emulator VM while testing some apps and have since deleted the VM. However, when i sign into my gmail acc it has 'tap yes on your android x device to confirm it's you' (which i deleted). I have recreated the exact emulator VM and the same thing happens..
- iszomer 5y agoI've had this happen before with my OG GMail account -- the one when we needed an invite to sign up. Back in the day there were no "account security" beyond the username and password, not even 2FA, backup codes, security questions, etc. At least Google doesn't recycle usernames unlike other services and account retention is trivially automatic if you use an Android phone.
- endorphine 5y agoThis absurd struggle strongly reminds me of the themes in Kafka's novels: The Trial, The Castle.
- Delfino 5y agoYeah, living abroad I am constantly running into issues like this and it's quite frustrating.
- isarat 5y agoIn the safety perspective, dormant accounts might be prone for exposed passwords (reused passwords, exposed via other services etc.) and easily an attacker can hijack your account. I had similar experience where a dormant apple account was hijacked and unable to recover. Apple also follows similar philosophies to sign in from a real device for recovery. Have you tried recovery options?
- exodust 5y agoRecently signed up to mailbox.org after losing one of my longtime Gmail accounts due to this Google nonsense. I had correct password AND correct secret answer to my own secret question I set years ago, but was denied entry because of new device, or time sine last login or whatever. The explanation it gave made no sense, sending me in circles with no recourse. So I decided enough is enough. Their system is broken. When a user has both password and secret answer, there is no reason to deny them at that point. Good riddance Gmail.
- hysan 5y agoYes, posted here about it too.[1] There is no solution. You are locked out forever once Google does this to you. [1] https://news.ycombinator.com/item?id=21168834 https://news.ycombinator.com/item?id=21168834
- iamtedd 5y agoJust yesterday, I got two 'Google' verification codes to my mobile number out of the blue. No number, so I've only got 'Google' as the sender to go on. * My password is very long and complicated and stored in a password manager * I don't use any device I don't own and can see the moment the SMS messages came * I have no other indication that I've been compromised I'm thinking it's more likely that someone else added my phone number as a second factor to their account. Google: Just one damn easy thing would give me more information about the situation and allow me to act appropriately: Have the email address associated with the verification code in the message.
- TheChaplain 5y agoThis is another reason why I recommend to use your own domain (from a 3rd party registrar). If you can't, at least set a mail-forward to a different mailprovider (I have an old hotmail account) so if you get locked out, at least you can receive mails. Use Google Takeout at least twice a year. Another option would probably be to use Office365, I don think it's that expensive and I guess you would have the possibility of getting real support?
- eitland 5y agoIf you live in EU or EEC I wonder if this isn't covered by GDPR? Aren't companies required to have a way to get a manual review of anything an AI does? And aren't they also to safeguard your data? I'm not a GDPR expert but I know GDPR is a bit larger than many expect.
- sercand 5y agoGoogle added one of my employee's LinkedIn account address as our LinkedIn URL to our company Google business profile. We have contacted google support about this to change URL to our own but we got response like following: I understand that you are referring to an incorrect LinkedIn profile which is visible under your business profile in Google. Please be informed that information from social profiles are collected by automated algorithms. There's no way to manually remove these social profiles from our end. This is something which is driven by Google’s algorithm, based on the visibility, ranking, web presence, etc. of the particular business page. We at Google do not have any manual control over this. Google and its algorithms are going bad and they have no control over it. It is getting ridiculous.
- deleted 5y ago[deleted]
- mediumsmart 5y agoalphabet just needs your account. You don’t have to access it. all is good.
- aesyondu 5y agoIt would be interesting if this becomes a monthly hackernews post like the monthly hiring, where people with problems with their Google or Facebook or "insert Tech Giant here" account with intentionally no human customer support, would post their account problems and whatnot. It would never happen of course, but it would be interesting.
- menage 5y agoLast time I had to deal with Google's account recovery (10 years ago when my mom fell for a phishing scam) there was an option to pay a few dollars to get to talk to a real human in a customer service / operations department. Does that still exist?
- prafullss 5y agotry to connect same network/wifi you have used to connect your device or native place where you have frequently used your device. you can open you Gmail id. If this not help you to fix , try to reset password in a Desktop/Laptop on chrome browser
- prafullss 5y agotry to connect same network/wifi you have used to connect your device or native place where you have frequently used your device. you can open you Gmail id. If this not help you to fix , try to reset password in a Desktop/Laptop on chrome browser.
- ComodoHacker 5y agoI've lost two Gmail accounts (like firstname.lastname@gmail.com) because of this. Now I'm using only nickname accounts and not tying them to anything important.
- gue7890dfg 5y agoI have a theory: It is impossible to have anonymous reliable email accounts nowadays. Today a lot of data are collected. For those data to have any value they need to be quality data, so that they can be used. Many would think for AI, but what is more lucrative maybe is to sell them or services based on them to government intelligence in USA. Similarly, maybe government is also putting pressure that accounts of big providers are not mass used or hacked by adversaries. Google may have some hidden deals. Starting with Facebook, Google, Microsoft as the biggest ones, you are forced by all means to have non-anonymous accounts. Google accounts measures point to one direction: tell them your identity. Make sure you are in that location, no VPN, tell them you phone number when you register an account, etc, so they know it is you for sure. This makes it impossible to use Google, etc, anonymously. It is impossible to open any Google account, as I do not want to drop my VPN, or give them a phone number. I also have 2-3 accounts of Google open many years before, when these restriction were not so bad in place. I was relying on them for various things. I assume since a while, that I will loose access to those any moment and I am not using those much anymore.
- dusted 5y agoOh that is CREEPY.. means if I lose the devices I'm using to sign into google, I can't sign into google no more, even if I have the password.
- vorhemus 5y agoMost big tech companies now use "conditional access" for their login with the hypothesis that this increases security. Even if it does, it leads to a drastic reduction in user-friendliness as OP has seen. It is like saying: The best way to prevent unauthorized access to our servers? Let's just turn it off!
- avodonosov 5y agoFrom other user experience problems introduced by Google (what they did with Chrome address bar) I have impression some incompetent non-computer people are making thechnical decisions there.
- anshumankmr 5y agoI was setting up my blog and using AppScript to automatically write add my new posts to Firebase. It is still a WIP, I granted the script the permissions I needed and somehow after that Google labelled my account on my main computer as suspicious (which I have been using for years). So whenever I switched from my personal computer to my office one, it used inform me someone suspicious tried to use my account and asked me to reset my password. This happened multiple times (and it isn't possible since I have set up 2FA and have a very complicated password). When I switched back to my personal computer, it once again used to ask me to reset my password. This became infuriating and after a while I just gave up and switched to Firefox completely (where I have not had the issue again). *The script I wrote is a variation on the one I wrote while working at my company (where we use AppScript to sync some sync data to Firebase... the same issue never occurred for me while using my company's account)
- smukherjee19 5y agoI wonder if paying up money for this Google Workspace Individual[0] will make me more immune to possible lockouts like this... Or is it just more sensible to jump to another paid email provider like Fastmail? [0]: https://workspace.google.com/individual/ https://workspace.google.com/individual/
- perth 5y agoInteresting question for you hn people. My email domain is my website domain and I just use Google’s email servers. If Google ever nuked my account is it trivial for services to resolve that my email pointed to a new provider?
- pllbnk 5y agoI have a very similar issue where I enter my (correct) password, Google recognizes it but says they need some additional verification where they require one of my previous passwords to be entered. I don't know my previous password, so I am locked out of my account. What's funny is I have another account to which the Gmail of the said locked account is connected, so I can send and receive emails by the locked account, but I cannot use it for any other purpose. It has been the trigger due to which I had switched my primary email to my own personal domain and a better service provider for a few bucks a month. It's painful and I'm still in progress of transferring all communications to the new domain, however it's totally worth it because I have a sense of actual control.
- nuker 5y agoApple Private Relay enters the chat
- mcantsin 5y agogoogle is evil
- foxfluff 5y agoAnecdotally, getting arbitrarily blocked and locked out of your stuff is the single biggest practical security today problem today for me (maybe it isn't for non-technical users who reuse weak passwords, install catpicture.jpeg.exes and random software from the internet, log in using public computers or other people's PCs..). I don't believe I've ever had passwords compromised. The only time I know I had malware was when I was a kid and installed a runescape autominer.. I've had some close calls with software vulnerabilities (I patched opensmtpd mere hours before bots started attacking it), but that's rare. haveibeenpwned only shows involvement in the last.fm compromise, which is a no biggie since I wasn't 1) using the service any more 2) using the same password with other services 3) using that email address with anything worth caring about. By contrast, I've been burned by service providers blocking me many many times. They call this security but how is the equivalent of "we decided to take all your mail and not deliver it to you, and changed the locks to your apartment so nobody can get in" security? It's security in the same sense as "we decided to burn all your money so nobody can steal it, hope you're happy." As a consequence, I've tried to cut out as many services and third parties out of my life as I can. It's an uphill fight though, and most services are hell bent on adding points of failure. E.g. where my bank before supported OTPs (in addition to login & password), now they require a phone too. It's probably not a matter of if but when I get bitten by this; I've had a Samsung Xcover physically break. I think any notion of security should include secure access for the relevant party. If you can't access your stuff, security has failed (unless it can be demonstrated that there was an active attack going on and the only way to prevent it was to block everyone.. which these overzealous blocking systems in place can't demonstrate).
- toastal 5y agoMy 'favorite' is SMS and other proprietary app-based 2-factor auth. My phone broke while I was traveling through Laos. I was going to be returning in a couple days, I could speak the language well enough, so I didn't have any immediate need to get a new phone (and the pickings were way too slim in a country such as Laos). What I thought would be a good idea was to purchase a new device online to be shipped to my apartment on my return. I tried to log into my online shopping account but most payments are always locked behind 2FA with SMS being the only option. Bank transfers worked too, but that as well was locked behind SMS. So in order to buy a new phone, I needed a new phone to buy a new phone. Almost nothing in the country support TOTP or WebAuthn, etc.. and the times they do they just call it "Google Authenticator" encouraging users give those keys to Google as well instead of supporting FOSS TOTP. At the same time I got my income via TransferWise, and their 2FA is some proprietary BS in their app instead of generic TOTP that I can back up on my laptop. So I couldn't get extra money to my foreign account to pay for it. A few months later I needed to use PayPal and was locked out of my account on similar grounds. My foreign account I didn't have my old phone number because it's pretty customary to rotate numbers on prepaid plans here, and my US account was using Google Voice (because it's tedious to maintain a US SIM card for the 2 times a year I need it) and they removed SMS support for Voice while not giving an alternative for authentication. The best part is that to get support from PayPal about authentication you needed to first authenticate to message support. Needless to say, I straight-up refuse to use PayPal now and direct message vendors about supporting an alternative (either widely or for this exception).
- throwaway55852 5y agoThis is a long shot, but if you have a spare Android phone lying around consider doing a factory reset on it and signing in with that account during the initial setup. My situation was somewhat different. I had a rarely-used account with no recovery email/phone. When I entered the password correctly using a web browser, I was asked to provide a (new) phone number so I could be sent a verification code before continuing. I didn't want to provide a phone number, so I tried to log in with that account during the initial setup of a freshly-reset Android phone and it worked (allowing me to add a recovery email). I'm curious if this strategy helps in your case. (You mentioned getting a new phone, but I assume you are signing in on that phone after it has been set up, which may be different to signing in during the initial setup.) By the way, in your reply to a comment on 2-factor authentication (https://news.ycombinator.com/item?id=30051366 https://news.ycombinator.com/item?id=30051366) you said you had a recovery account. There is a difference between enabling Google's "2-Step Verification" and having a plain recovery email/phone (though from other comments it sounds like you can get locked out even with 2FA, and not all 2FA methods are equal). P.S. If you want to allow people to contact you privately, consider adding some contact details to your HN profile.
- throwaway55852 5y agoAnd a suggestion from https://support.google.com/mail/thread/123734419/i-am-locked-out-of-my-gmail-account-even-with-recovery-email-and-code-help?hl=en https://support.google.com/mail/thread/123734419/i-am-locked... (written by a community member who is labelled as a "Product Expert"): > Try letting the account sit for a full week with NO sign in or account recovery attempts. Just leave it idle for a week. This may help any suspicious activity flags to clear allowing you to attempt account recovery with more success.
- Khaine 5y agogmail security is infuriating, particularly if you are off travelling the world. You enter your password correctly, you use MFA, and still google can be like nope no email for you. Its incredibly frustrating, and there is no recourse, no one you can call. I get its trying to help protect people, but you know, if it creates friction for the user, you have fucked up. And google's automate everything is admirable, but where there are no feedback loops, it is worse than useless, as no-one knows something is broken and needs fixing.
- wruza 5y agoProtip: log in to youtube with this account. (Or is it “log into”, “login to”, not sure) Less reliable way: log out of all google, login to all of your “best” accounts, then login to this one. When you are logged in and google knows they were logged in at the same time before, restrictions get relaxed (there is sort of a “skip security” button, or a similar setup).
- 4cao 5y agoMirrors my experience. I moved away from Gmail for most of my mail a while ago for privacy reasons, and in anticipation that something like this would happen eventually. Not much later, I was locked out of a Gmail account I had for an extensively long time (created back when Gmail was still in beta and by invitation only). I know the password, I know the recovery e-mail address, and have access to the recovery account, yet I'm not allowed to access the Gmail account or recover the password regardless. Go figure. The account was used mainly for all kinds of registrations where I expected I might end up getting spammed but I definitely wasn't doing anything suspicious with it. I didn't bother too much trying to restore it but any attempts would have likely failed regardless.
- muthuraj57 5y agoHad similar issue before. My and my friends are traveling to a different city and one of my friend's mobile went missing during our trip. The contact we were about to stay in the city is in that mobile (saved in his Google Contact thankfully). When he tried to login his account in my mobile to access it, Google wouldn't let him. He had to use the secondary email he registered with email(which is from Yahoo) to send a verification code and use that to login to the Google account. He also forgot the password for the secondary mail id and finding that was another story.
- lucideer 5y agoHad this same issue: thankfully managed eventually to regain access (by temporarily re-invigorating an old half-working phone) but have since moved all essentials off Google. Absolutely outrageously dangerous system, no way I can trust that service with anything remotely essential again.
- joejohns 5y agoSame exact thing happened to me, I tried reaching out for help in Google and yet, to no avail, nothing happened.
- husamia 5y agois paying for Google One subscription give me any support?
- CRConrad 5y agoThe only rules of thumb I can come up with are these: 1) Log in on everything now and then (hm, maybe gotta so that myself soon); and perhaps even more important, 2) When getting a new device / phone number / email address, log in to everything from the new one before getting rid of the old one. That way, you can jump back to the old and confirm the validity of the new. Then set up the new phone number for 2FA / email as your backup address / recognised login device... Only then can you dispose of the old.
- 2162372559 5y ago
- jayzyone 5y agoGoogle is not the only one. Amazon froze my account for suspicious activity. I had a fire and had to suddenly move leaving a delivery at locker also changing my address and password all on one day. I forgot to change the phone number, cause that phone died in the fire. I waited out my suspension, now I can't get into the account with my new phone. Top it all off I'm deaf and can't talk to customer service.
- y3sh 5y agoWhen my kids were born I created gmail accounts for them to save the name for when they become old enough to use it. This worked well when I did it from home, but for my last born I created his account *on the hospital wifi*, saved pass in 1pass. A couple years later I tried to login to his account from home and got thrown into this recovery hell. I visited that same hospital wing a year later to try "a prior location", but it didn't work. As a result I unintentionally caused the very problem I was trying to prevent.