7 ms·
> Needless to say, I will never again use gmail for critically important things. That's a hot take. If it was critically important, you'd have 2FA and a recov
by abider 5y ago
> Needless to say, I will never again use gmail for critically important things.
That's a hot take. If it was critically important, you'd have 2FA and a recovery phone number associated with it - which would have prevented you from getting stuck in a trust-fail situation to begin with.
Use whatever service you want, but your takeaway from this situation is a bit absurd.
Edit to add: I'm not saying Google's algorithm is perfect here, but relying on heuristic voodoo ("I use the same IP, so I should be fine") for "critically important things" instead of using well-established means of securing access to critically important things (e.g. 2FA, backup mobile number) is a bit insane.
- ethanbond 5y agoSomething can be critically important for a person to access on-demand and not be something they’re especially concerned about an attacker accessing. Two completely unrelated dimensions of access needs.
- M3L0NM4N 5y agoThey are not mutually exclusive. An attacker accessing a service can hinder or even completely stop your ability to access that service (i.e. change your password).
- buck4roo 5y agoOr do things that trigger the provider to force you to change your password. See: Apple ID, where failed password attempts (by anyone) causes Apple to force users to change their known password.
- PaulHoule 5y agoWith Google’s nonexistent customer service I’d be afraid of being locked out for any arbitrary reason and having no recourse no matter what recovery procedures I prepared for. Contrast that to my bank where I can go to the branch, show ID, and get problems logging in resolved.
- jck 5y agoI personally had a great experience with google support when I once stupidly locked myself out of my account. The whole thing was resolved in about 3 days. However, google customer service is definitely erratic since loads of other people have had bad experiences. The best thing to do if you're using Gmail is to enable 2fa and backup the recovery codes offline and somewhere safe. This could probably get you into your account without needing to talk to support.
- jiggawatts 5y agoI have never heard of anyone anywhere ever being able to access Google support once they were locked out -- you need to be logged in to access what little tech support they offer.
- gerdesj 5y ago"With Google’s nonexistent customer service" Quite. If you play the game then all is well but if you don't then you are given very short shrift and no recourse to a higher power or anything at all. There is very little oversight. If you fall afoul of the "algorithm" or whatever bollocks is running the show, then you have to fall back on calling them out on the socials. Get enough traction on that and lo: "soz, lol, we failed here but your <whatevs> is important to us ... in this case ... etc ..."
- josephg 5y agoA plug from a very satisfied customer: I pay $5/month for Fastmail. I've emailed support before and reached a human within hours. They helped me with my problem, because it was their job and I'm paying them to do it. Email is too important to rely on a free service which has a history of shutting people out, at any time, for any reason.
- knob 5y agoDitto. I'm a satisfied Fastmail paying user for years
- Andrew_nenakhov 5y agoActually, I specifically declined setting up a recovery phone number because I accessed it from the location where receiving codes would be impossible on my phones. I always accessed it from the same IP using my own VPN server, entered the correct password, and still Google decided that they are 'not sure that it is not really me, try again later'. No thanks.
- taxyz23 5y agoWhat about downloaded back up codes ? Phone push approval? U2f key? Authenticator app? Can't imagine complaining about being shut out if you didn't have at least one or all of these set up. Google even nags you about setting these up.
- Dylan16807 5y agoWhy can't you imagine that? This gatekeeping you're doing is rude and doesn't make sense. 2FA's very purpose is to increase shut outs when enabled.
- smileybarry 5y agoIt might be 2FA's very purpose, but I've found that a 2FA-less account is a lot more distrusting of logins. Some of my relatives don't have 2FA set up and they got more "verify it's really you" prompts compared to my personal MFA'd account.
- Dylan16807 5y agoBecause Google is abusing the concept.
- zenexer 5y agoI have 2FA and a recovery email on my Gmail account, yet I have run into this issue. If Google thinks something is suspicious, it will decline your 2FA codes and recovery attempts—it will just tell you that you entered the wrong code. Only after you finally get back in do you find an email in your inbox explaining that the correct code was entered, but Google blocked it because it was suspicious. This happens to me from time to time, and the only way I can get back in is through Android. I keep an Android phone on hand at all times for this very reason. Don’t blame the human for inadequate preparation; I assure you, no amount of preparation will save you from Google’s AI.
- sgjohnson 5y agoMicrosoft & Zoho Mail does the same, and when they do it, they also revoke all of your app specific password for good measure, so SMTP is a toast too.
- joshuamorton 5y agoIf you're entering a code, the 2FA method you're using is still susceptible to mitm-style phishing attacks, which is what this kind of location based check is securing against. You'd need a push notification or yubikey based 2fa check to get the same level of security.
- zozbot234 5y agoAIUI, they do send push notifications if you happen to have a mobile device that's logged in to the same account. Maybe they should do the same for the "suspicious login to an unused 'secondary' account" scenario? They're already sending "recovery" emails, so it wouldn't be that big of a change.
- zenexer 5y agoI have several YubiKeys linked to my account. It will decline those as well. It demands that I sign in from Android sometimes, seemingly for no reason.
- 5y ago
- afandian 5y agoI do wonder how many people will be locked out of their lives when they change phone numbers. 2FA across the industry seems to have rolled out this critical dependency without drawing enough (IMHO) awareness.
- matheusmoreira 5y agoThe only way to avoid getting into a trust-fail situation with Google is to be completely signed into it at all times so they can monitor you 24/7.
- trasz 5y agoYou didn’t understand the story. It’s google that’s using heuristic voodoo for critical things.