3 ms·
I wonder how many people suffer identity theft versus how many have a working recovery email but are denied to use it because some algo finds it suspicious that
by DoingIsLearning 4y ago
I wonder how many people suffer identity theft versus how many have a working recovery email but are denied to use it because some algo finds it suspicious that you moved country or logged in from a linux machine?
The key takeaway is not about how we should promote 2FA or how we should promote long ass passwords, the main issue at hand is google's neglectful lack of customer support.
I was once caught in this non-sense many moons ago. But I learned my lesson, I absolutely do not rely on any google products for anything that has any potential to impact me personally (with the unfortunate exception of the Android OS on my phone).
Google as a brand is absolutely dead in the water for anyone that has woken up from the 'Don't be evil' kool-aid of the early days.
- judge2020 4y ago> the main issue at hand is google's neglectful lack of customer support. Customer support is the main entrypoint into 99% of sim swapping attacks and would be similarly for any targeted account takeovers. What sort of information do you possibly think would be enough to prove someone actually owns a Google account over the phone?
- UncleMeat 4y agoI've heard of some system for reviewing identification like drivers licenses in extreme cases, but homeless people are largely not going to have access to this either.
- ImPostingOnHN 4y agothat is a phenomenal question that deserves to be answered by the highly paid engineers at Google they're smart, I'm sure they can find a way, even if it contains such horrible, detestable ideas like "more support staff" and "more training for support staff"
- joshuamorton 4y agoCompanies with highly trained support staff regularly fall for these attacks. The answer has been figured out by the highly trained engineers. It's "don't provide account recovery options that bypass 2fa". Yeah that sucks for a segment if people, but it sucks less than regularly getting your account stolen due to a social engineering attack. There really, truly, doesn't exist a panacea. You don't have and can't create an oracle that knows when an account recovery attempt is legitimate or not.
- Eisenstein 4y agoWhy don't we expand physical IDs into the network space. We need some way to verify ourselves online that doesn't rely on a private company and a TOS.
- UncleMeat 4y ago> the main issue at hand is google's neglectful lack of customer support Imagine Google had a full service customer support system for account recovery that everybody could access rapidly. How would a homeless person use it? They lose all their possessions regularly so they don't have a reliable form of identification. They'd need to enroll their drivers license (which they probably don't have) in the system and then still have that license when they need to recover their account. Or they could be vouched for by a pre-enrolled trusted party account that does have strong authentication systems. But... homeless people are often transient and don't have access to regular support networks like a family member or social worker who could be enrolled as a backup account. In fact, you can already enroll as backup account if you want to. > Google as a brand is absolutely dead in the water for anyone that has woken up from the 'Don't be evil' kool-aid of the early days. Google has a pretty bad reputation at this point on tech blogs and forums. But, believe it or not, it actually shows up near the very top of trusted brands when 3rd party analysts do surveys on the wider population. Maybe this data is wrong, I don't know. But it is interesting.