16 ms·
Tell HN: Locked out of Gmail account even after right password, recovery email
My mom got locked out of her 10yr gmail account. She doesn't have access to the phone number she added for 2FA. This is after she has the right password and also has access to the recovery email.
This basically locked her out of her whole online life because for all other social accounts she uses sign in with Google.
There is no human support, and their support website says if you cannot recover the account, create a new one.
- tmaly 4y agoIs there a way to download all of your emails from gmail in case such a situation happens to you?
- tuukkah 4y agoCould she try to regain access to the phone number?
- CrimsonRain 4y agoNever sign-in with social logins for accounts you are not prepared to lose.
- deleted 4y ago[deleted]
- atoav 4y agoWhich is why you don't use such services for important things.
- comboy 4y agoWhat do you use? Host your own e-mail? Or use some provider that will close in a few years? Should non-tech person get a tech degree and then with that tech knowledge spend 2 weeks choosing their multiple providers and then carefully make decision which one to use for different accounts? How about if somebody can't afford and don't want to use Apple? Just not use smartphones? We're at the point where government services (at least here in EU) require you to use smartphone unless you provide written document that for some reason you are unable to. I've always been "don't like it don't use it" guy and that's a clear and simple argument but it doesn't work in the context of where we are currently. Just the fact that govs and banks only provide you google play services and app store apps which they often require you to use is enough of a problem.
- atoav 4y agoI use a mail hoster with my own domain. This way if they ever do shanenenigans I just have to migrate the IMAP directories to someone else and point the domain(s) there. However I have been using the same mail hoster without troubles for the past 10 years.
- mnahkies 4y agoI actually wish there was a way to opt-out of the suspicious login detection mechanism. I've certainly had nerve racking moments where my login has been flagged as unusual and I wasn't sure if it would let me in (and I'm completely locked out of my childhood account though it's not been used in over 10 years) It's a good feature for those with the password "password" but if you've used a strong single use password it just gets in the way
- iforgotpassword 4y agoYes, this so many times. Whenever these posts hit HN there is some people going "well if they don't do this then a lot of accounts will get hacked" - fine! Fucking make my account vulnerable if I want it to, the chances I get hacked are probably still 10x lower than getting locked out by Google's shit AI crap "protecting" accounts. And well if it does happen, those same people can at least have their "told you so" moment. Fucking bullshit.
- bheadmaster 4y agoI completely agree. If I get hacked, it's on me. Google can even add a "you can't sue us for damages" clause in their Terms (which they probably already have) - just don't lock me out of my own freaking account.
- MattGaiser 4y agoI’m curious if they can do this/how politically feasible it is. In Canada, banks have this for things like e-transfers and preventing suspicious transactions. However, when people acknowledge the warnings and still go ahead anyway, they cry bloody murder and the bank ends up refunding people for fraudulent activity the people explicitly authorized after being warned.
- rexf 4y agoThis is a good point. 2FA is a great thing and I think everyone should use it. With that said, I don't want 2FA on my alternate/testing/dev accounts. I simply don't want demo accounts linked to my phone number. I'd like to opt-out of "standard security" (MFA) and accept the risks on non-primary accounts.
- theplumber 4y agoThat's part of the vendor lock-in deal.
- can16358p 4y agoIn this case, more like lock-out though.
- BiteCode_dev 4y agoI'm sorry for the pain it will cause you. I had a similar story with my own accounts. It's just lost forever, luckily I had many others, and didn't associate my whole life to any single account or provider, nor used social sign in, so it was not life altering, just a bit of work. But selfishly, I hope those kind of story get published more and more so that people finally realized that what we told them not to do the for the last 20 years was not just for the sake of it. People don't listen to preventive talks. We see that with cyber security, climate change, and so on. They only start to move when they get hurt. I wished people would have listened to us when we advised not to give everything to GAFAM, not to put everything online, and not everything on one provider. And certainly not to trust them with being on your side. So they wouldn't have to get hurt. But this is not how we, as a specie, learn. We need to get hurt. So make sure a lot of people know about this. Not just in the hope to get the account back, but because maybe more people will listen this time.
- TedDoesntTalk 4y agoHere’s why I down voted you, even though you’re right. “I told you so” is never helpful when someone is in pain. It actually exacerbates their pain.
- MichaelZuo 4y agoWasn't that their point though? That most folks only really learn through sufficient pain?
- TedDoesntTalk 4y agoYes. That comment is unhelpful and only exacerbates the pain.
- MichaelZuo 4y agoI don't want to nitpick but if they believe that most people only really learn through pain then they would likely also believe exacerbating pain is indeed helping.
- dataflow 4y agoThis might sound dumb, but if the phone number belongs to someone else now, could you just call/text them and explain the situation and (eventually) ask them to read you the code or something? Admittedly it'd sound suspicious as heck, but if you're willing to provide sufficient proof of your identity and somehow offer a reward in a safe manner, the person might understand and be willing to help? You'd have to be pretty smooth about it, but it seems worth preparing for and giving it a try. Alternative idea: If you're really desperate, you could even try to dig up the phone number owner's address and show up at their door or something and explain it that way. (Note I'm not recommending these per se; I'm just pointing out what's possible. Obviously be very careful to consider everything before doing such a thing.)
- angry_octet 4y agoSocial engineering works for hackers all the time, imagine if you had an actual mom doing it.
- broeng 4y agoI'm not sure what context Google provides in those text messages, but if it is just a one-time code; how would I know, you aren't trying to log into one of my accounts?
- dataflow 4y agoThis is literally why I said it would sound suspicious. Most people wouldn't be able to tell. Which is why I said you'd need to provide some kind of sufficient proof of your identity (or some adequate alternative) to address their fears.
- Elhana 4y agoIf you are desperate, you might have to just trust that person your login/password, ask them to login to your acc and change/add phone number.
- 4y ago
- jeffbee 4y agoIf there was a workaround for 2FA, it would be pointless.
- YPPH 4y agoCorrect, but it's probably not necessary to permanently lock someone out. All that is needed is a significant delay. You could just block access and say "come back in 28 days". In the meantime, warning SMS and email messages could be sent to the account contact alerting them of a possible takeover attempt with a link to disavow the attempt.
- llanowarelves 4y agoThe workaround is supposed to be real human customer support. Banks dont permanently lock you out of your account/card if you forget the PIN.
- bmitc 4y agoYep. I got locked out of my eBay and GitHub accounts for two different reasons, but through their human support I was able to recover the accounts.
- oefrha 4y agoBanks verify your identity when you open your account, which they can refer to later on. Gmail does not, so any “proof of ownership” you can provide is circumstantial.
- bell-cot 4y agoBanking is a heavily-regulated industry. Their regulators can (& have) seized & shut down a fair number of banks. And the Rich & Powerful would react very badly to any "a bank can lock you out of your money..." precedents. Basically (& sadly), you're comparing blueberry waffles to the moon. I blame the English usage of "account" for both situations, even though there's very little similarity between a bank "account" and a Gmail "account".
- 4y ago
- JonathanBeuys 4y agoThat's the problem with 2FA as it is done these days. The second factor is not under your control. It begs the question if 2FA makes your setup more secure or less. In this case, it backfired. People are trusted with their own keys to their apartments, cars and houses. Will we ever trust people with their own keys to their social life?
- CannisterFlux 4y agoGoogle forced 2FA for (all?) accounts earlier this year. I turned it off immediately, because I was more worried about losing access than someone guessing my password (besides, Google has other mechanisms already in place like IP checks or new device checks). I can't believe Google would activate 2FA on all accounts. It seems too easy for it to go wrong for normal people.
- abrookewood 4y agoThere are a couple of options to fix this: - Use QR code and save the image to another secure store (I save them in KeePass) - Use an MFA program that allows you to back them up or restore to a new device (I use Authy)
- sh4rks 4y agoAnd what if you somehow lose access to your password manager?
- justsomehnguy 4y ago
- oezi 4y agoHas anybody ever had any luck with getting a lawyer to write a letter to Google (or other big tech) in such a situation?
- jeffbee 4y agoWhat would it say? My kid persuaded me to use 2-factor login and I lost one of my 2 required passwords and now I demand access to my account?
- deleted 4y ago[deleted]
- angry_octet 4y agoThis is not 2FA that has been deliberately enabled, Google is applying an account security heuristic that says « the login is from a new device, this user has a cell phone, require confirmation via the phone ».
- Thorrez 4y agoThe question seems to say it was deliberately added as 2FA: >She doesn't have access to the phone number she added for 2FA Disclosure: I work at Google but not on anything related to this.
- oezi 4y agoI would provide written testimony that you are the account holder and evidence for instance a photo of an ID, email excerpts, email send to the recovery address. Anything that would get Google to update the 2FA phone number.
- probably_wrong 4y agoI kind of did, but I'm in the EU and I had no 2FA. When I got locked out of my account I wrote (in pen and paper) to their GDPR team saying essentially "You don't have to give me my account back, but you do have to give me a dump of my emails". After some back and forth (they told me to use Google Checkout, which I couldn't access because I was locked out) they decided that giving me the account back was easier, and they did.
- satysin 4y agoSorry for the stress this is no doubt causing your mother. Unfortunately I have seen similar and they never recovered access. It is just lost to the void that is Google support for their free services. Yes I know it is the risk you run using a free service but I feel there should be some official process for a real human to get involved to get the account back. As you say you can lose access to your whole damn world these days. It is crazy we have so many protections for your account getting hacked yet absolutely nothing to recover the same account should some automated system determine you are not you.
- msh 4y agoGoogles services are not free. You pay by letting them show you ads and use your data.
- satysin 4y agoYes, yes we all know that. That is being very pedantic though as to OPs mother (and the vast majority) Gmail and the related Google services were 'free' in that she didn't enter her credit card details and pay a monthly/yearly fee like she does with Netflix.
- msh 4y agoNo, its not being pedantic. If it was a truly free service that the company provided for no income at all I could excuse their lack of support. Not having support for customers you make money on is despicable.
- satysin 4y agoIf you ask any random person on the street "is Gmail free?" they will answer yes just like Wikipedia calls Gmail a free email service and if you search for "best free email services" Gmail is usually top of the list. I fully agree with you there is an agreement that the user gets Gmail (or Google service) at zero monetary cost in exchange for them showing you ads and using your data however they see fit. And you can argue if that is 'free' or not but to the vast majority they see these things as free, rightly or wrongly. Is 'free' the wrong adjective? Perhaps but it is what is used for a non-paid service. > Not having support for customers you make money on is despicable. I agree. Like I said it is crazy there is no real support process to get your account back when there are a lot of processes to keep your account safe.
- waitforit 4y agoWait a few days. It may be possible at a later date. I'm not storing cookies when using GMail and at a time I regularly got those suspicious login type messages when the browser updated to a new version. At one point I had to click a link in the recovery email and enter the month when the account was created. Pretty much guessed several times until nothing worked. Tried again a day or a few later and got in again.
- brettgooo 4y ago> Wait a few days. Sounds exactly like what someone named waitforit would say
- unsafecast 4y agoThe account was created a few minutes ago. My guess is that they did that to reply to OP, hence the username. Still funny though.
- cycomanic 4y ago> At one point I had to click a link in the recovery email and enter the month when the account was created. Seriously?! Who comes up with these security questions? This is such a useless question, on the one hand it's insecure because it is a 1/12 chance of guessing right, but also who remembers what month they created an email account? I would venture a guess most people here couldn't even get the year right (I certainly couldn't). Seems the question is only useful to lock out the legitimate owner.
- mimimi31 4y ago>on the one hand it's insecure because it is a 1/12 chance of guessing right, but also who remembers what month they created an email account? IIRC, they require both month and year, so there'd be a bit more guesswork involved. I added the exact creation date for all my Google accounts to my password manager when I learned about this verification method.
- 4y ago
- jules 4y agoDid she log in from a different geographical location? That can matter.
- chrismorgan 4y agoI have absolutely no respect for geographical location checks in this kind of thing. I can immediately think of five services that I occasionally log into that in practice email me about every new session, at least two because they always do and at least two because they think it’s from an unknown location (not device, location), even though they always list my location as Melbourne. Seems to me they’re either lying about remembering locations at all, or have all implemented it as a check for exact IPv4 addresses (/32), which is a very poor proxy for geographical location and almost completely useless for a significant fraction of internet users. I use mobile data for my internet connection. My public IP address changes from session to session.
- saurik 4y agoI ran into a situation earlier this year where I tried to log in to my Google account in a pinch on someone else's computer and I could not because, even though I did NOT turn on any fancy 2fa options and had ONLY ever wanted Google to use my phone number or alternative e-mail address (at MOST) for such purpose, they refused to let me log in unless I approved some special 2fa mechanism in the YouTube app I had logged in on a Google Fi Android phone that I only use for testing and had over a thousand miles away from me at my desk. It was ridiculous. In another, non-Google case, Apple once demanded that I provide the answers to challenge questions for an account I didn't use often even though I had my username and password correct. To me, the challenge questions are something that should only ever be used to verify in the case that I don't know my password, and it took me three days of trying against the rate limit to get enough tries to figure out the spelling of the answer for one of my questions. What made it really ridiculous is that the only reason this account existed was to give me access to developer account that was actively billing my credit card that I couldn't access... at least with Apple there was a customer service representative who was willing to try to figure something out as they agreed that it was ridiculous that I was paying money for something I couldn't even log in to cancel (though she wasn't sure if she could actually do anything...).
- esalman 4y agoRe. Apple, I bought an iPad, took it to another country and gave it to someone. After a few years when they tried to access it, they could not. I contacted support, they wanted to see the purchase receipt before helping to unlock it.
- sdkgjajggaf 4y agoI hate this, but you MUST enable 2fa in the way YOU want, or else google will opt you into "2fa" you never consented to on some app you don't remember installing. Maybe hugely insecure but I enable google authenticator then put that recovery code and key everywhere I can.
- tmoravec 4y agoAfter reading this comment I tried to disable the 2FA with phone apps that I never asked for. Curiously, I'm not even signed in the app - I'm signed in Google Calendar but I get the prompts in Gmail app where I'm signed into work account only. Anyway, it's not possible to configure 2FA in the way we want. The Google prompts configuration says "To turn off Google prompts on a device, sign out of your Google Account on that device." There's no way to enforce the Authenticator. Not even make it default.
- cloudking 4y agoHave you tried account recovery? https://accounts.google.com/signin/recovery https://accounts.google.com/signin/recovery https://support.google.com/accounts/answer/7299973?hl=en https://support.google.com/accounts/answer/7299973?hl=en
- Elhana 4y agoWhen you enable 2FA, you are given 10 backup codes for that specific reason and it tells you to print/save them, but everyone just ignores it - do it now. You can also add multiple phone numbers, I got two just in case I loose one for some reason. Like if I loose my mobile, I'd need to sign in to google to locate it and I can use another number (my wife) to get 2FA code. And I have authy with my google 2FA by default, you can have multiple devices as well.
- Eleison23 4y agoIt's too late now, but this should be a lesson to anyone to always cultivate the MFA methods in their accounts: review them on a regular basis, remove methods that aren't secure or safe, and always, always print out those emergency codes on a sheet of paper and store it safely away, offsite if possible. If your mom had printed out paper codes, then she'd have recourse to a sure recovery method at this point. Also worth a try is to pay for Google One. Rumor on the streets says that paid members have a better chance at bending the ear of a human customer service representative. It may be worth the extra few bucks per year.
- pcthrowaway 4y agoI have a gmail account I never enabled 2fa on, or set up a recovery email. However, it had an old phone number I haven't used in >8 years. 2 years ago, I tried logging into the account, and google told me I needed to verify an SMS message due to logging in from a new location (I had logged into this account from Canada before). I tried calling the old phone number, but it's disconnected. So unless I want to move back to the U.S. to try to get that same phone number again, I probably won't be able to access this account until someone gets that phone number, and I manage to talk them into passing along the authentication message
- jwr 4y agoI believe it is time for regulatory support. I know it is fashionable to mock the EU regulatory efforts in the US, but the EU has a tendency to step in once something reaches proportions where regulation is actually needed. Ridiculously high roaming charges, for example, have been eliminated through regulation. Once you are the dominant provider of something that is nearing life-essential utility status, you should provide support and escalation routes, and you should be accountable.
- llanowarelves 4y agoIt and food regulation are some of the things they have way better.
- creato 4y agoPhone companies are regulated, and the solution to this problem is basically for google to allow itself to become vulnerable to social engineering, just like phone companies are.
- Semaphor 4y agoI don't know what the situation in Germany is, but as I only ever hear about those issues from the US, I assume its something ridiculously bureaucratic, which might actually be a plus in this case?
- MattGaiser 4y agohttps://www.enisa.europa.eu/news/enisa-news/beware-of-the-sim-swapping-fraud https://www.enisa.europa.eu/news/enisa-news/beware-of-the-si... Here is an EU article warning about it.
- Semaphor 4y agoAccording to the linked [0] report, of the two providers in Germany that were asked, one had 1-10 incidents, and one 11-30. In a year. So I guess those issues exist, it’s just a minority issue. The related German Wikipedia page [1] and almost all articles I can find also mainly talk about the USA. It seems you can usually add another required password for phone changes, but mainly it’s just not an issue. No ridiculously bureaucratic requirements, though. [0]: https://www.enisa.europa.eu/publications/countering-sim-swapping https://www.enisa.europa.eu/publications/countering-sim-swap... [1]: https://de.wikipedia.org/wiki/SIM-Swapping https://de.wikipedia.org/wiki/SIM-Swapping
- throwaway2056 4y agoIf you are geeky/nerdy just remove phone number and add QR code based 2FA. Print that QR code and scan it on your phone (as a courtesy to your mum). Yes, victim blaming but better to do this as a help rather then hosting your email service for your mum.
- unsafecast 4y agoHow do you do that without access to the account?
- tinaclaussen 4y agotoo little too late...
- hsbauauvhabzb 4y agoI had nearly this exact thing! The backup email wasn’t working. My mom was able to leverage an existing session on thunderbird to access her emails. Her SMS auth was failing as she’d change numbers. She managed to convince a phone provider to give her the old number so she could successfully authenticate. Still mad about the lack of ability to provide proof of ownership, we had ample evidence which would have held up in court if required. But alas, google are worried about their immediate bottom line instead of their long term viability.
- hsbauauvhabzb 4y agoSide note: I swear this is an issue with very old google accounts. The backup email address was working but refused to validate, we also had the password. If you work at google, please submit a bug report on behalf of us pleb public users who have no access to such features! And if you work for government, please propose legislation which fixes these asshole ghost companies!
- oefrha 4y agoHuman support can be social-engineered or bribed. You hear about SIM jacking, OG Instagram account takeover, etc. because of human support. It certainly sucks, but in this case you lost your second factor, which is very different from the other flagged-as-suspicious-and-locked-out-permanently cases.
- zelphirkalt 4y agoWhen there is a human in the support loop, there is also a chance to reverse a mistake though.
- iLoveOncall 4y agoHmm, yes, that's actually the exact behavior that I expect from 2FA. To not let people in my account without the code. I fully sympathize and understand that the outcome is bad, but this is just a system working 100% as expected.
- hijp 4y agoThis is happening to me with facebook, without 2fa. I temporarily disabled my account for a couple years as they promised you could log back in at any point to restore it. fast forward to today and even though i have the same email and password combo they are stuck in a loop asking me for my passport/state id, which i’ve provided dozens of times at this point. sucks because i have a bunch of memories locked in that account and can’t contact a human at FB.
- qot 4y agoDid your failed log-in attempt reactivate your account? Can your friends see your old facebook account now? Please check for me, because I'm in a similar situation but have been hesitant to try logging back in.
- hijp 4y agoThat's a good question! I didn't think to look until you asked. It looks like it didn't, which is a bummer because then I could have asked my friends to get my photos...
- blarg1 4y agoAn idea would be to have more than one account on different providers and have all their emails forwarded to each other, but make sure the forwarded emails arent forwarded again. Might go do this now.
- unsafecast 4y agoA good preventive option that costs a bit of money is to not tie yourself to any of the providers by just buying a domain name and pointing MX at a gmail account or something. So long as you back up your emails periodically, you can always switch providers in 10 minutes and nobody will even notice.
- trhway 4y agoSimilar with Yahoo recently - had an almost 20 year old account, and suddenly it wants verification on a long gone phone number. Good that the account was used mostly for various registrations and non-critical communications. Still a lot of history and context de-facto gone. A kind of personal mini-Alexandria library fire :) Similar situation with Hotmail went better - as the phone number was gone, the system offered an alternative - i had to provide previous passwords, recent emails recipients and subjects.
- cycomanic 4y agoIf she lives in Europe or California could she not make a request on all the personal information that google holds on her? That would at least get her the emails back, not likely to get her access to linked accounts though.
- hansvm 4y agoYou're probably fucked. I still have a bricked phone from the onboarding process there. Somebody has had an open ticket to fix it the last few years. I was able to get my W2 by showing up at the Googleplex. They seemed knowledgeable and friendly. Is a day-trip an option?
- JakeWesorick 4y agoIf she is logged in on any other device, even if that device is offline, you can use it to get past two factor auth.
- _8j50 4y agoTry a different IP and user agent (user agent of a browser you normally use) and avoid vpns. I will pull my hair out if this works for you.
- jwilk 4y agoAs a data point, when Google decided that knowing the password and the SMS verification code is not enough to get access to my account, I tried again with a different ISP, and that worked. (The first thing I did after regaining the access was to delete the account.)
- egorfine 4y agoIf I ever leak my Google password, the last thing I would want is for someone to bypass the 2FA on it. So I certainly hope that there would be no way around it.
- ddevault 4y agoWe see these posts several times a week. If you are reading this and you still rely on Google: what the hell?
- bell-cot 4y agoGenerally, humans are very good at "it won't happen to me" denial. And kinda-morbidly curious about the misfortune of others. And always looking for "the one little trick". And...
- rexf 4y agoMigrating off your primary e-mail provider with over a decade of history is not trivial. I could do it if I devoted a a lot of painful time to it. For non-technical family & friends? Forget about it.
- ddevault 4y ago1. Sign up for new email address 2. Set up auto forwarding 3. Done
- bell-cot 4y agoIn context, isn't that dependent on Gmail faithfully keeping your account open and the auto forwarding working correctly, long-term? I have seen people bitten pretty badly by "if I set up X in Gmail, they'll faithfully keep doing it..." assumptions.
- ddevault 4y agoYes, but I omitted step four: 4. Gradually move things over to the new address as you notice things which still use the old one, possibly over the course of years. Eventually you will run out of reasons to keep your gmail account and you can just close it. I migrated from gmail using this approach and it was not difficult in the least.
- 4y ago
- refurb 4y agoThis happened to me. I had the password, same recovery email, but phone number was one I no longer had access to. Turns out it was a IP location issue. When I traveled back to the same city I created it, I never got the 2nd challenge. The password was enough. I could then update the phone number. It's really nuts. I mean, if you know 2 out of 3 security challenges (password, recovery email, but not phone) suddenly that's enough to lock you out?
- samuel 4y agoOne of the reasons I pay for Google One storage is that in case something like that happens to me I will be able to do something legally, since I'm a customer and I'm not getting my service, right? (And my identity is tied to my credit card, so it can be verified easily). I'm probably too naive but I can't think anything better. I'd gladly pay some money just to avoid this scenario.
- supernova87a 4y agoCan you explain by what process being a paying customer with Google Drive/Google One helps you recover your account if experiencing what OP described?
- samuel 4y agoAs I said, I'm probably in the wrong, but my plan is: - Try to reach Google's One support instead of the generic Google Gsupport. Since they are paying customers, may be there are humans involved at some point. - If that fails, the next move is to take the legal path. There are several ways of doing so before going to court. I assume that once so trivial reaches any lawyer of the company it will be fixed immediatelly. If it doesn't, given that the company has valuable and confidential information that's not accessible anymore the case could be strong enough to reach a judge, even if the amount itself is very low (20eur/year). It's expensive and will take time, but it's the best I can devise.
- Nursie 4y agoThanks for reminding me to open up thunderbird and get it up to date with my google email. It would be bad to be cut off, for all the reasons you have given in the intro, but it would be even worse to lose all my mail as well.
- dejj 4y agoI have that looming above me. I lost access to the 2FA phone number a year ago. Google puts me in a login authentication loop when I try to change the phone number, even after logging in to the account. My previous phone provider deleted my number. They only told me by SMS, which I never received, because I kept the phone off. I used it on only for restoring accounts. Now I wait for the inevitable to happen. I use Protonmail. And I will lose access to GMail eventually. Then it’s time to GDPR the shit out of them.
- martin-adams 4y agoI wonder if it's practical to set up email forwarding to backup account so you can at least get password resets from other services that use your email address. Is it common to have a Google login on another site, then password reset to 'de-google' it?
- VladimirGolovin 4y agoJust wanted to say that I always upvote threads like this, just to help people get proper customer support that they deserve.
- znpy 4y agoTry and get a lawyer involved, it’s basically your only chance.
- Al-Khwarizmi 4y ago2FA is a step backwards, at least in the way most services implement it where you totally depend on a phone (I know there are other ways to do 2FA). I know that passwords are insecure (or at least, most people's passwords are) but I'd rather have that than tying all my identity to a phone. Since I started using the internet in the 90s I haven't ever had any password-related incident that I know of. Now I have a constant fear of my phone being lost or stolen. I do have an export of the authenticator files, but what if it fails, or if the phone thief starts doing bad stuff since some services are going so crazy with 2FA that they relax the rest of their security? (I have seen Yahoo mail sometimes not asking for password at all, just some SMS code). I only use 2FA where it's mandatory (unfortunately, more and more services) and I wish it were forbidden to make it mandatory, at least in this form where you totally depend on a phone.
- weberer 4y agoI really like the MFA implementation in 1Password. You can even have it autofill from the browser plug-in so you don't need to go find your phone whenever you need to log in to AWS or whatever.
- kleiba 4y agoI'm pretty old. I've been using computers for a long time, when it was still just something a selected few would do and when it certainly wasn't common that everybody had "a PC" at home. Forget internet. I've made CS my profession also many, many years ago, certainly before mobile phones (I'm talking _any_ kind of mobile phone, not smart phones in particular) were a thing. I'm setting all of this context up just for the following mini rant: eternal september is a thing. With all IT now tailored to the unwashed masses, some things had to give. Like, as you say, "most people's passwords" are insecure, but they can also be made very secure without too much effort. The tech-savvy folks are aware of that but the moms aren't - so now _everyone_ (including us who wouldn't really need it) have to deal with nuisances like 2FA. Computers used to be tools for professionals, now they're basically household appliances. It's a net win, I would say, because life has improved for society as a whole. But something got lost along the way, too.
- simonebrunozzi 4y agoThe crux of the problem is that gmail is, for billions of people, both their primary email account, which is superbly central to many things that we do in 2022, and the way in which we get authenticated and essentially "manage" our online identity. These two things would ideally stay separate. Of course, an expert in Computer Science would certainly have his/her own tld domain with email, and maybe use gmail only for proper email work, right? Well... Not so sure about that. I'm a tech person myself, and my gmail is my online identity. I would suffer the same fate if I were to go through the same issue as OP's mother. Perhaps there's space here for a startup, or a service, that allows you to fix this. Something that would make regulatory bodies not too unhappy about it.
- rexf 4y agoE-mail as online identity is both convenient and a huge source of risk (if Google's automated system goes wrong). I wonder if Google could offer real customer support. I know offering support goes against everything Google stands for, but I'm sure many people would be willing to pay non-trivial amounts of money to get actual support from Google. So if you unfortunately get locked out of your google account, you could pay for support that can actually resolve your issue. (I realize paying to fix your problem may rub some people the wrong way. However, I would rather pay for a support ticket than be locked out of my account forever.)
- jabbany 4y agoThis sounds like it would give rise to perverse incentives. If this were the case, Google would now be incentivized to cause problems (e.g. lock you out for "suspicious behavior") so that you'll then pay to get it "fixed".
- MichaelZuo 4y agoCS that can't be reasonably gamed or bribed is at least the level of senior dev. Would you pay $200/hour for customer support?
- deleted 4y ago[deleted]
- 0-_-0 4y agoReminder to set up automatic email forwarding of all your gmail to a secondary address. I recommend Protonmail. Also schedule Google Takeout to regular intervals.
- luckylion 4y agoIf Google locks you out of the account, will emails still be forwarded?
- Havoc 4y agoShould be yes. The forwarding has nothing to do with identity/login
- account42 4y agoIf you are willing to take proactive action then don't settle for anything less than getting your email on your own domain.
- UncleEntity 4y agoI got locked out once with very little hope of recovering my account (hit the password guess limit or something) but luckily I was still logged in on my old laptop so could change the settings enough to get in again.
- ReptileMan 4y agoWhen you create 2fa with google you get couple of one time codes. Try to fish them out.
- hooby 4y agoI feel that many of the answers here, which explain what could have been done beforehand to prevent this - are not very helpful to someone who's already locked out of their account. It's never gonna be possible to 100% prevent any possibility that could cause loss of access to your 2FA. Some people will always fall through the cracks - whether that's due to their own negligence, lack of technical understanding or some algorithmic false positive doesn't really matter imho. The real problem here is, that there's nothing that can be done to resolve something like that, AFTER it already happened. Not even if you were willing to pay for support to help you. If you got good contacts, are famous, manage to go viral or something, you might be able to actually get help - but as a regular, boring, everyday person, you're just fucked. The only "advice" you are gonna get is: "you should have done this or that beforehand..." - and the obvious answer to that is: "I would have, had I only known!" The only thing you can do, is post your story on HN and Twitter, and hope someone from Google reads it, and goes out of their way to actually help you - which obviously is AGAINST standard company procedure.
- bagels 4y agoIt might help one of us who haven't been googled yet.
- ElCheapo 4y ago>"I would have, had I only known!" log into Google giant banner appears "Hey, is this still your phone number? If it's not you better change it otherwise we can't recover the account!" click 'no' change it to a new one done.
- hooby 4y agoPeople still fall through the cracks.
- ElCheapo 4y agoYes, and people still fall through literal cracks and die every day. You can't force people to be truthful online, just like you can't fill up every crack on the Earth with cement. If I ask you to confirm you haven't changed your number and you outright lie then I'm sorry but it is what it is.
- einpoklum 4y agoLessons from this situation: 1. Prefer an email provider with human support - which probably means paying money; otherwise, choose a free email provider with a better record on these matters than Google/Alphabet. If you do use Google: 2. Prefer independent sign-in on websites which offer signing in with a Google account. 3. Periodically back up your email someplace that's not Google, preferable on your own HDD and with a copy on removable media.
- kome 4y agoMoral of the story: don't use google, don't set-up 2FA.
- qprofyeh 4y agoSomething similar happened to my mom earlier this year. She lost her phone (stolen) which through the YouTube app was her 2FA device.
- account-5 4y agoI upvoted this post so hopefully it stays long enough on the front page for someone at Google to see it and do something about it. It's the only thing I can do to help, I'm sorry for your mum. I've said it before, Google cannot be trusted with anything important. They don't care about their users because the users (info) are a product they sell to their actual customers. There's no incentives for Google to provide their cashcow something like customer support, because the user is not a customer.
- adrianwaj 4y agoWait isn't Google sitting on a dormant cash cow in helping all us lemmings?
- ALittleLight 4y agoIf she is still logged in somewhere, on a laptop, desktop, phone, whatever, then she can go and remove 2FA (no, you don't need the 2FA code to remove 2FA - or at least you didn't ~1 month ago).
- throwaway1851 4y agoI’ve been planning to migrate off Gmail, and stories like these are increasing my sense of urgency about it. Google shows such callous, reckless disregard for its users’ lives. I feel kind of stupid for trusting Google with this much power in the first place!
- reactspa 4y ago2FA is becoming a huge problem. One day, I unintentionally left my phone home. At work I was unable to log into my Google account without my phone. What a clusterf**k. (And I never opted for 2FA. It was forced on me by Google).
- sumedh 4y ago> (And I never opted for 2FA. It was forced on me by Google). Looks like you have an option to disable 2FA, I just checked my account, apparently I did that many years back.
- sho 4y agoI've recently been transitioning over to paid email (I chose fastmail, it's great, but there are many others) for pretty much exactly this reason. Free users are just useless eaters to big companies. Fine when it works, shit out of luck if anything goes wrong. I had a near miss with an old phone number - it worked out in the end but I was left with no illusions about my total lack of recourse if it hadn't. Turns out, when I asked myself the question "is my email worth $50/year?" the answer was "yes". It's been a hassle, not gonna lie, and I may never fully get everything transitioned - but it's an important service, and if it's important I want a prompt and easy resolution to any problems. That costs money. Why did we ever think free email was a good idea?
- switch007 4y agoAs a long-time Fastmail user, I'm curious if anyone has ever recovered their account and how it compares to Google? More generally, can you get someone on the phone? I can't see a phone number in the Contact Us section of their site. EDIT: I also checked their most expensive plans ($90/user/year), and it doesn't have different support options.
- barneygale 4y agoGoogle employees: quit your jobs and do something (anything) positive for the world.
- turnerc 4y agoWait around a week without any sign in attempts or attempts to recover, should allow you to progress.
- renewiltord 4y agoSMS 2FA is vulnerable. Just hack yourself.
- bborud 4y agoWhat good alternatives to Gmail exist today that have proper support?
- MrPatan 4y agoVery sad this happened to you. To everybody else reading this: Get your own domain, get an email through it on fastmail, migrate all your accounts to it. It will happen to you!
- yread 4y agoGoogle login is getting worse and worse. My son school gives them a google login. I can login on a PC. But on Android you can't login with Chrome because there can be only one google account linked to a device. When I try to login with Firefox (even with the correct password), it says that they can't verify it's me and that I should contact the domain admin.
- sumedh 4y agoIs it a Google Policy or a policy set by the school?
- yread 4y agoYou think it's a device policy set by the admin? But I'm not trying to connect the device to the domain, just login with FF
- tinaclaussen 4y agoSchool policy? Complain to the school not here.
- hnarn 4y agoMy mom has two numbers for 2FA SMS on Google, one is hers and one is mine. I’d highly recommend anyone in any situation that involves phone numbers for 2FA to never only use one. If that’s not feasible, use one of the other “phone independent” options (like recovery codes on paper).
- sumedh 4y agoHow do you setup two numbers in 2fa?
- tinaclaussen 4y agoAdd it in https://myaccount.google.com/signinoptions/rescuephone https://myaccount.google.com/signinoptions/rescuephone
- zmmmmm 4y agoI know everyone will say "this won't happen to me" but you might be surprised how quickly even a technically savvy user can stumble into this situation with a few wrong clicks of the mouse. In my case, I did the Google "security checkup" and clicked "yes" when it asked if I wanted to improve my security by using my phone as a security factor. I thought this was just going to cause it to generate those helpful "Did you just sign in" prompts. No: that option actually signs you up to use your phone as a hardware security token which requires you to physically connect your phone through its USB port. Guess what doesn't work on my phone? My freakin USB-C port (!!!!). Eventually I found the loophole that signing in from the hardware key device itself prompts you to use a different 2nd factor and I was able to disable the security that way. It boggles my mind that I was able to enable that security option without proving I could actually use the hardware device to unlock first. But it completely activated it without me ever doing that.
- MmM218 4y agoI got the same problem on a couple of Google accounts. The only pitfall advice from Google was to try to log in from an old machine or a previous location. This has never worked, and accounts are lost as there is no way to be in contact with a human to assist.
- aurora72 4y agoThis time is different. It's got something to do with G$$GLE's policy to charge the Gmail users who happen to use their E-Mails under the so-called "G$$GLE Workspace". I know this for sure because I use Gmail under "G$$GLE Workspace" and today I'm greeted with a message like this "Your 14 day trial period for G$$GLE Workspace has ended. If you want to use G$$GLE Workspace , start a (paid ;) subscription." All of this happened after I've been using it for more than 12 years!
- londons_explore 4y agoGoogle could have logic to prevent exactly this case... Have the security requirements for entry to the account reduce after a timeout and notification period. Eg: Since we haven't been able to verify your access to this account, we have 1 final option for you. Click this button to begin the recovery procedure: * We will message anyone currently logged in to ask if they want to allow or deny you access. If you are logged in from another device, you can allow access there. * If there is no response in 7 days, we will message the recovery email addresses and phone numbers to ask the same. * If there is no response in 7 further days, we will message the 10 most recently emailed email addresses from the gmail inbox to ask if you should be allowed in. The message will contain your name, and request the recipients contact you and give you a code you can use to unlock your account. The process still has the problem that scammers will farm discarded/temporary gmail addresses. Dead peoples addresses might easily be taken over too...
- account42 4y agoThe general idea is great but 14 days is wayyy to low to allow random addresses that have not been pre-approved to many any decisions about your account. And most recently emailed is also hardly the best metric to determine people you might trust.
- ister 4y agoIt happened to me a few days ago, after a reboot of my internet box. I suspect the box IP changed, but didn't check. I didn't have recovery email, and I managed to recover my account by googling sth like "gmail set recovery email" (=> https://myaccount.google.com/intro/recovery/email https://myaccount.google.com/intro/recovery/email). There I could login after having answered the 'secret question', and this gave me back my access to gmail.
- pSYoniK 4y agoFor those that have a new phone number or have changed their number - sometimes you might have your old phone number in your payment profile (or something along those lines). That number might still be used by Google even when you change your number. So you can end up in a situation where you update your recovery phone number, but that old number still shows up. It took me some time at a point to get rid of this one to ensure that it works. Also, 2FA will still trigger even when you turn it off. I had turned off 2FA because I don't care about this account and because I kept having issues with it due to the countries I lived in over the years. I logged into a machine that got a fresh install and got prompted to go through 2FA and get a text. But this was turned off. So I'm sorry to hear about this, it's a real big issue and I ask everyone here who cares about privacy and who cares about a better tech environment to push their friends and family or followers to move towards more privacy respecting alternatives that HAVE support, that WILL assist you if something like this happens. Even in a worst case scenario (all emails being lost), getting back access to the account itself can make a huge difference... So please, support those who hit on issues if you can somehow and promote alternatives for those who can afford them (and most people in the west will generally be able to afford the 1USD/1GBP/1EUR a month some services will charge).
- Brajeshwar 4y agoHey Harsh, Sorry to see this (after reading on On Deck) and here is how I would try. No guarantee but an idea. Add your mom to Google One Family plan (buy for one month, you don't have it). Now, the support on Google One is quick and are actual people. I was extremely surprised by this and asked quite a few time if they are real people (they are). Try talking to them and see if that works.
- Dr_ReD 4y agoThe main problem is that Google asks you for a recovery email address and then won't actually let you use it for recovery. This gives a false sense of security and creates a lot of gotchas.
- fattybob 4y agoI have the same issue / I guessed it was hacked and taken by some other, luckily I got it isolated from all my logins and i made a new account ! Can’t help but wonder who has it, also cannot comment on how unhelpful google are in resetting the access!