6 ms·
Things I can recommend in your situation, which helped me in the past, in no particular order: * log into other gmail account (with a long history) using Chrom
by jacekm 5y ago
Things I can recommend in your situation, which helped me in the past, in no particular order:
* log into other gmail account (with a long history) using Chrome without any addons, log out and then immediately try logging into the primary account (ideally google should ask you if you want to add another account)
* log in from the same location. I once spent two years abroad, and could not log in to one of my accounts. I regained access only after returning to my home country
* if you are working in an organization that owns an IP range, try logging in from work, i.e. do not use publicly available ISP.
You'll get best results if you can combine two or more of these points. Unfortunately even following this advice you are not guaranteed to be successful...
For the future reference, the only prevention that I know which works 100% times is using YubiKey for 2FA. 2FA with TOTP codes often helps unlocking the account, but I had cases where even the codes did not help.
- alecco 5y ago> using YubiKey for 2FA Today Google/Gmail suddenly logged me out and asked me for the hardware key, and I thought no problem as I have OTP with my Password Manager, but OTP didn't work. I had the key somewhere else. Luckily after insisting a bit Google gave me the option to use my mobile Gmail app to verify it's me (note it was not Google Authenticator, why did they made me install it?). All this hassle even though I've been on the same ISP/IP range and computer for weeks. No VPN or anything. On top of the multiple authentication options, I'm going to add a second hardware key in case I lose my main one and Google decides it's the only way to log in. Edit: the OTP option is not there anymore in my Google account 2-Step Verification, but it did ask for it and it failed.
- jacekm 5y agoI once had a situation where I didn't have access to my YubiKey but I had backup codes (not from the authenticator app but the 10 codes you are given when you set up 2FA for the first time). I could log in but I thought I'll remove the YubiKey from the account and set up TOTP (Authenticator) instead. It turns out you cannot do this using only backup codes, you have to have the key! So if you loose your key and run out of your 10 codes, you may loose the access to the account forever! It seems that the only way to prevent this is to have two YubiKeys added to the account...
- mlac 5y agoThey do recommend having two keys associated with the account. It’s not cheap, but you can pick up a USB-C small format one and leave it in your computer & get one for your key ring that does NFC / Bluetooth. One is always with you, one is conveniently on your main computer. You can get the least expensive model as a third, off-site backup.
- AnonC 5y agoAll hardware dies at some point. What if both the Yubikeys die? What if the third one was already dead before and it wasn’t noticed because it wasn’t used recently? This sounds like too deep a maze for I don’t know how much benefit.
- alecco 5y agoI don't know why they removed OTP. I like handling ALL my logins through a single Password Manager.
- mlac 5y agoIt’s really up to the user to determine whether it’s worth it for them. I work in security, so I eat my own caviar in my personal set up and like to test things out. All hardware dies, but I also have different keys from different vendors (not just yubico), purchased at different times. The likelihood that all 3 die at the same time is very low. Whether it prevents an attack that would be successful without the physical key (e.g. SIM takeover) is something I won’t ever know. Both of those scenarios are very low likelihood. But to have this level of security requires extra work, and part of that work is regularly testing that the keys still work. With the increasing account lockouts, this thread is showing me that physical keys may have another advantage. Most people are set up so that their email account is a “Jesus Nut” [0], so this extra level of security is well worth it as it protects banking, personal files (g drive & photos), password resets / password manager, and purchasing capabilities. An approach I like is using one’s birthday as a reminder to reset important things - check security keys, check batteries in critical items, test security system, etc. [0] https://en.wikipedia.org/wiki/Jesus_nut https://en.wikipedia.org/wiki/Jesus_nut
- kccqzy 5y agoSimilar case here. One of the Google accounts I have has three 2FA setups: SMS, TOTP, and Yubikey. One time I tried logging in I didn't have my Yubikey with me. I thought no problem I'll use the TOTP authenticator app. Google told me I can't login even though the code was correct. There wasn't any way to address that except by actually using the Yubikey to log in. I'm using a fresh install of Chrome with no addons.