4 ms·
I have 2FA and a recovery email on my Gmail account, yet I have run into this issue. If Google thinks something is suspicious, it will decline your 2FA codes an
by zenexer 5y ago
I have 2FA and a recovery email on my Gmail account, yet I have run into this issue. If Google thinks something is suspicious, it will decline your 2FA codes and recovery attempts—it will just tell you that you entered the wrong code. Only after you finally get back in do you find an email in your inbox explaining that the correct code was entered, but Google blocked it because it was suspicious.
This happens to me from time to time, and the only way I can get back in is through Android. I keep an Android phone on hand at all times for this very reason.
Don’t blame the human for inadequate preparation; I assure you, no amount of preparation will save you from Google’s AI.
- sgjohnson 5y agoMicrosoft & Zoho Mail does the same, and when they do it, they also revoke all of your app specific password for good measure, so SMTP is a toast too.
- joshuamorton 5y agoIf you're entering a code, the 2FA method you're using is still susceptible to mitm-style phishing attacks, which is what this kind of location based check is securing against. You'd need a push notification or yubikey based 2fa check to get the same level of security.
- zozbot234 5y agoAIUI, they do send push notifications if you happen to have a mobile device that's logged in to the same account. Maybe they should do the same for the "suspicious login to an unused 'secondary' account" scenario? They're already sending "recovery" emails, so it wouldn't be that big of a change.
- zenexer 5y agoI have several YubiKeys linked to my account. It will decline those as well. It demands that I sign in from Android sometimes, seemingly for no reason.
- smileybarry 5y agoThat's especially weird. I've had Google decline TOTP/Google Authenticator and SMS one time when I was troubleshooting a OAuth issue, but declining U2F? Are you logging in from various different VPN servers daily, or just through the same few ISPs?
- zenexer 5y agoNo VPNs, just my home network with an IP address that rarely changes. What seems to throw it off is when I log in from "conflicting" platforms, particularly iOS + Android. I also have multiple iPhones for work, and it very much dislikes that. When it gets in this state, nothing will work besides going to g.co/sc on Android--it can't be any other platform, regardless of how long I've had the device--and approving the code request there. If I approve it from any other device, even with a YubiKey, it'll give me a code on g.co/sc, but I'll be told it's invalid and I'll get one of those emails telling me the code was correct but declined due to suspicious activity. I appreciate the attention to security, but c'mon, it's a YubiKey, and I'm logging in from my usual residential location.
- fleddr 5y agoIf we reason from good faith and consider that this is intentional and not a bug, have you considered that Google did not implement "blocking suspicious 2FA" just to mess with you? That perhaps this deals with a very real threat? Google has no incentive to make it difficult for you to log in, it's the exact opposite.
- vidarh 5y agoThe problem is not really that they do it, but that they don't adequately inform users about this risk and that they fail to offer proper support and alternatives when it gets triggered. If they offered proper support a whole lot of the user despair and anger would disappear.
- Spooky23 5y agoIt’s definitely a point that should be made. Typical TOTP tokens are weak MFA in takeover scenarios. Especially considering that people have a bad habit of syncing them between devices. What a lot of the grumpy posters here probably aren’t mentioning is that many ate probably doing high risk signal stuff like running through public VPNs. Google and Microsoft know a lot about what you are doing and what scammers do. They score risk accordingly.
- AnonC 5y agoI agree to some extent, but also consider that whoever designed this may not be as intelligent or as widely experienced in certain matters as is necessary for the real world.
- zenexer 5y agoI have no doubt it deals with a real threat. That doesn’t change the fact that I’m regularly unable to log into my Google account. Usually it happens when I’m using multiple devices simultaneously—for example, Android and iOS. It’s understandable that Google considers that to be suspicious, but if Google isn’t going to learn on its own, there needs to be some way for me to confirm that nothing is amiss. It’ll ignore everything from TOTP codes to YubiKeys.
- 5y ago
- prirun 5y agoI think we need to quit calling it AI, and instead call it AS: Actual Stupidity
- yuliyp 5y agoThis is an incredibly harsh and naive take. Authenticating logins at scale is an incredibly hard problem. There are tons of phishing campaigns and attackers seeking to get access to Google accounts all the time. That they sometimes get it wrong sucks, but calling their attempts to do so "actual stupidity" is pretty rude.
- oxapentane 5y agoSome time ago I used to run a userscript which replaced all occurrences of "Artificial Intelligence" and "AI" with "Artificial Idiocy". Added some charm to buzzword-heavy press releases :D.
- docmars 5y agoAgreed. The moment we allow AI to take the blame for irresponsible decisions made by the humans who designed and maintain said AI, is the moment we stop holding people accountable for real damage done. Account lockouts are bad enough, but more serious things driven by AI are bound to reveal their fallibility. I sincerely hope tech workers have the integrity to take responsibility, judging by the current political climate and its participants' willingness to venture into thinking (surrounding the value of human life, among other things) that was considered taboo not long ago. The moral and practical capacities of AI will reflect the limits of those designing them, at best.
- sebastien_b 5y agoOr “Artificial Incompetence”
- AnonC 5y ago> If Google thinks something is suspicious, it will decline your 2FA codes and recovery attempts—it will just tell you that you entered the wrong code. Seriously! What! The! Hell! I too have thought before that having 2FA (and linking a phone number, which I hate to do) would avoid tripping in such situations and that the systems would consider a different situation (like a different IP address/location, a different browser) as reliable enough with 2FA. But this irks me a lot. I don’t really use Gmail much and have other paid alternatives, but I have some old stuff that may be mildly inconvenient if I were to lose them. Need to download the data and dump these accounts.
- deleted 5y ago[deleted]