4 ms·
Well, this is not a solution for your situation, but for anyone reading this who doesn't want to be in your situation ENABLE TWO-FACTOR AUTHENTICATION on every
by textadventure 5y ago
Well, this is not a solution for your situation, but for anyone reading this who doesn't want to be in your situation ENABLE TWO-FACTOR AUTHENTICATION on every account you have anything remotely valuable.
I once got a Hotmail account hacked and Microsoft was very much able to recover my account as long as I was able to provide them with enough information (old passwords, personal information, etc) to prove the account was mine, so I'd really try all Google avenues possible because it's your best bet for recovering your account.
If you can't access your money that's a banking issue, talk to your bank.
- hatware 5y agoCell phones are also not good second-factors, preferably a physical offline device like a yubikey.
- ghaff 5y agoEspecially for international travel, it's also a good idea to print out key travel information and carry it with you (also cash/spare credit cards etc.). Phones get lost/broken/etc., credit cards get flagged for fraud/left in restaurants, etc. It's easy to just assume that how you do things day to day will always be available--and then they may not be and you are in an unfamiliar place. Ask yourself what would happen if your phone crapped out and/or if you lost your wallet. Very unfortunate for sure. But there are mostly things you can do to not make it a crisis.
- agentdrtran 5y agoEnabling two-factor can help, but if you are the victim of a phishing attack as many are, one would expect one of the largest tech companies on the planet to have a plan for that.
- tluyben2 5y agoThis will only get worse. Most people have no clue what mfa is and when I tell them they find it incredibly annoying and/or forgot how it worked again when they login from somewhere else a month later. I had people deleting Google authenticator or Authy from their phone because they forgot what it was for and their phone was getting slow…
- mitchdoogle 5y agoIt's crazy that the onus is on individuals, who, as you point out, are often ignorant about online security practices. Put the onus for security on the businesses who safeguard information, and they will have a big incentive to force users to use more secure methods of logging in, they will do more verification for account changes, etc. End users won't have any excuse for not using MFA when they can't do anything without it.
- tluyben2 5y agoAgreed, and if people don't want to use 'difficult tools', they could swap it for privacy: do KYC for your email account. Then you, in this case, the business could freeze the accounts until you go through the motions of proving you are the owner. Tech savvy people can then stay 'private'. Amazon has a simple KYC form for when you lose your otp device (I lost access to my sms and forgot to change to phone based otps).
- agentdrtran 5y agoAgreed, companies forcing horrible 2fa implementations are turning people off to the idea of using it at all on their personal accounts (even when it's far less onerous)
- madaxe_again 5y ago2FA is helpful, but you can usually call most service providers and get them to remove it. Often with totally inadequate security checks, like “what’s your phone number associated with the account, ok, great, I’ve removed the 2FA”. Can’t comment on Google, but I’ve had this with the British government, of all people.
- estaseuropano 5y agoNot true. I lost access to gmail because of 2FA - Google Authenticator to be precise. One random sunny day my 2 year old bit in my phone, thereby breaking it. A few days before i had reinstalled linux and apparently had not yet logged into gmail. So suddenly I have only unrecognized devices and no authenticator. Despite living in the same place, using the same wifi, etc, I simply cannot get back in since then. Its been years with dozens of attempts from any possible 'known' device, but there simply is no way. I know the password, I know previous contacts, i have old emails, i have the password, ... But even when I enter all the info Google requests for account recovery I simply get a screen saying they will get back to me - and never do. My fault for not having a backup sheet of codes, but I was too worried someone would find and abuse that sheet. Well, goodbye 10 years of email.
- Fogest 5y agoI keep a backed up list of all my 2fa codes in a password/key encrypted storage. I am trying to avoid the kind of situation you described. I have A LOT of accounts with 2fa now, and losing access to the 2fa app would be an incredibly frustrating issue as I would lose access to many accounts. At one point I actually had a couple backup codes for some important accounts in my wallet, such as to my email. My thinking was that if I ever lose my phone and need to login to my Google account on someone else's device I would at least have access to some backup codes to get me in ASAP.
- jonny_eh 5y agoThat's a huge inconvenience, but at least it wasn't stolen.
- doliveira 5y agoI think the threat model for most of us is online takeovers, not physical ones. Even if you live in a dangerous country like myself, criminals don't care about your email, so I don't think there's much danger in just storing the 2FA backup codes in your wallet. They're only good for when they've already input your password, aren't they? But I'd appreciate if someone from cybersecurity were to weigh in. What are the best practices for 2FA backup codes?
- 5y ago
- ryanianian 5y ago> ENABLE TWO-FACTOR AUTHENTICATION More than this: use a password manager that has 2FA built-in and use THAT as your google account MFA. The "easy" MFA with gmail involves approving new login attempts with an existing authed app present. But without an activated phone or other authed devices present, there is no way to authenticate to the GMail app to receive email. Apple replaced the back of my iPhone after I dropped it. They do this by putting a new phone onto your screen and then tossing your old phone along with its activation status. ESIM, so no way to activate it without the old phone (which is now screen-less and inoperable). I could not even activate my phone because TMobile required a OTP from my email which I could not access. (Apple did not warn me about this at all btw.) I was essentially 100% locked out of my account and unable to use voice, data, or access my google account until I could find a TMobile store to get a new SIM card and then use live-chat on the TMobile website to relay the one-time code from my laptop which thankfully was still authed. To say I was panicking about not being able to access anything was an understatement. Lesson learned: use an MFA mechanism that doesn't require an activated phone since you can't activate your phone without having access to your phone. Now I have my MFA details in 1Password which is restored as a part of iCloud backup.
- deleted 5y ago[deleted]
- tempestn 5y agoTwilio Authy is another option for those who don't want to integrate MFA with their password manager. It will sync across multiple devices and optionally back up to the cloud. (All E2E encrypted of course.) Honestly the risk of having MFA in 1password is extremely low to zero I'm sure, but I still feel safer with the two separate.
- davesmylie 5y agoThe other thing you should be doing is _not_ using the gmail.com domain for your email - at least for account sign-ups to important services. Buy a cheap domain and use that with your gmail account. All the convenience of gmail, but if the worst happens and you lose your account, you can pick a new email provider, redirect your email and you're back in business without losing access to all those accounts tied to your xyz@gmail.com email address.
- tempestn 5y agoI've always done this, but I've run an email server forever so it wasn't any added hassle to have gmail download the emails using pop. I'm curious how you go about it without running your own server. Do you pay for the google email service? Or just use your registrar's email forwarding to forward from your custom email to your gmail? Something else? I tried forwarding in the past for simplicity but found it results in a significantly higher rate of false positives in the spam folder.