4 ms·
I feel that many of the answers here, which explain what could have been done beforehand to prevent this - are not very helpful to someone who's already locked
by hooby 4y ago
I feel that many of the answers here, which explain what could have been done beforehand to prevent this - are not very helpful to someone who's already locked out of their account.
It's never gonna be possible to 100% prevent any possibility that could cause loss of access to your 2FA. Some people will always fall through the cracks - whether that's due to their own negligence, lack of technical understanding or some algorithmic false positive doesn't really matter imho.
The real problem here is, that there's nothing that can be done to resolve something like that, AFTER it already happened. Not even if you were willing to pay for support to help you.
If you got good contacts, are famous, manage to go viral or something, you might be able to actually get help - but as a regular, boring, everyday person, you're just fucked. The only "advice" you are gonna get is: "you should have done this or that beforehand..." - and the obvious answer to that is: "I would have, had I only known!"
The only thing you can do, is post your story on HN and Twitter, and hope someone from Google reads it, and goes out of their way to actually help you - which obviously is AGAINST standard company procedure.
- bagels 4y agoIt might help one of us who haven't been googled yet.
- ElCheapo 4y ago>"I would have, had I only known!" log into Google giant banner appears "Hey, is this still your phone number? If it's not you better change it otherwise we can't recover the account!" click 'no' change it to a new one done.
- hooby 4y agoPeople still fall through the cracks.
- ElCheapo 4y agoYes, and people still fall through literal cracks and die every day. You can't force people to be truthful online, just like you can't fill up every crack on the Earth with cement. If I ask you to confirm you haven't changed your number and you outright lie then I'm sorry but it is what it is.
- mistercheph 4y agoWhy would anyone willingly and knowingly do business with someone like you? This attitude is wildly inappropriate both in formal, business relations, and in private, social ones. To treat someone like that is something that should bring a person to bury their head in their hands out of shame.
- ElCheapo 4y agoWhat attitude? Asking your clients to be truthful in exchange for a mutually trustful relationship?
- mistercheph 4y agoShoving yet another banner in the user's face that is styled like every other banner ad you place in their way, including the one that begs you to download chrome or to sign up for google's latest service does not constitute a meaningful attempt to communicate with the customer. And the customer's blind dismissal of yet another annoying banner does not constitute dishonesty. It is completely disingenuous to frame this as though Bob walked up to Alice after lunch and asked her "Has the phone number you used for authentication changed?" and she lied and said "No". And it seems obvious that in most cases, users that lose access to 2FA methods are not asked "has your 2FA changed?" while they still have access to the account. It is far more likely that one day their cookies are reset or google decides it's time to reauthenticate and they realize that they changed their phone number when they switched phone plans a week ago, and they hadn't thought about the consequences.
- account42 4y agoWell if someone falls through a literal crack IRL then there will be emergency services ready to try to get them out and we don't just say they shouldn't have been absent minded so now they get to rot down there. And if a particular crack swallows up multiple people then we won't say that's life but find ways to fix that crack (probably even after the first person).
- McDyver 4y agoIt doesn't matter if you have a reminder, a banner, someone going to your door to ask you to confirm. If you miss that step, because you're in a hurry, your kid pressed the button while you looked away, or whatever, you shouldn't be immediately locked out of your whole life without recourse. We allowed ourselves to be held hostages by these companies, but we should know better now.
- ElCheapo 4y agoGoogle periodically puts that banner at full display when you log in. Even if you miss it one or two times it will come again. If you are so incompetent as to ignore a clear security warning that many times then you are responsible for your own actions.
- mistercheph 4y agoHow would someone be logging in if their current, valid 2FA is no longer accessible?
- prometheon1 4y ago> that many times If you're already logged into Chrome and logged into your phone, it might take a few years before you get to "many times"
- hooby 4y agoYou don't know how this person lost their number. How quickly they lost access to it. What actually happened. Maybe the last time this banner appeared, they still had their number. Maybe things just co-coincided with the worst possible timing. Stuff like that can happen. I'm really not comfortable calling them completely incompetent over this. Also there have been reports of people getting locked out for no fault of their own as well. And those people too have no chance to do something about it. But even if it is incompetence or gross negligence - as a software company, you'd still want people to be able to report that stuff happening, so that at least you get statistics that you can use to measure the effectiveness of any improvements you try to make. If those problems occur so frequently that it's no longer financially feasible for you to actually look into them... then maybe there's some incompetence going on at your own side, right?
- mrzool 4y agoIf only. An old phone number of mine is still somehow tied to my Google account. I can’t for the life of me figure out how to remove it. Google sometimes randomly decides to send the access code to my old number, which I no longer have, instead of using the new one. The only solution when that happens is to try the login again from an incognito window, hoping the Google decides to use the right number. Getting locked out someday is a very real possibility for me.
- crottypeter 4y agoYou can configure alternative phone numbers to receive the SMS code. (Family members, friends). They would only get a message if you hit "try another way" and choose one of your alternative numbers during the login challenge.
- sumedh 4y ago> You can configure alternative phone numbers to receive the SMS code. Where is this option?
- Elhana 4y agog.co/2sv, login, click on the phone option and just add more numbers.
- sumedh 4y agoThanks looks like I have disabled 2FA couple of years back, dont want to enable it.
- tinaclaussen 4y agoCareful or you will regret it... (either if the password is lost or if you get a new device)
- RMPR 4y agoOr if you change countries. The only thing able to save me was my open tab from my computer that thankfully I only put to sleep before travelling.
- raxxorraxor 4y agoI got locked out of paypal once, I could not complete the recovery process. I also could not register a new account because my payment methods were already used for the other login. After a waiting period of about 3-4 years they changed the process and I could indeed recover my account. Maybe sooner, but I discovered this by accident. I don't remember the details, I think I failed to answer a recovery question at the time. Certainly my fault, but there was no route to regain access until they revamped the whole process.
- nashashmi 4y agoI have a highly secure 2FA system guarding everything. But there are still so many points of weakness and potential ways to compromise the security in place. I am aware of them. I am also aware of all of the ways I can lose access permanently. We think we have internet identity system figured out. We don't. We are just pretending we do with stupid stuff like password, email recovery codes, 2FA, device auth, social network recovery, facial recognition, fingerprint, etc. So far we have leveraged brain memory, hardware device, face, finger, and friends for authentication. What else can we do to make this better?
- thephyber 4y ago> We think we have internet identity system figured out. We don't “We” do. There are companies that have very strong security and IAM protections. Others have chosen to invest almost nothing. Your vague wording conflates these two very different things. Some companies have a great concept of identity and have placed high value on identity verification. Free email accounts aren’t protected the same way retirement investment accounts are because they carry different risk profiles and different value.
- thephyber 4y ago> are not very helpful to someone who's already locked out of their account. One person posted. Hundreds or thousands read about it. The comments aren’t solely intended to OP and aren’t solely for this instance. I agree that there are few suggestions that will help OP this time. But that’s all the more reason that others learn to take the issue seriously before they encounter it.