6 ms·
Perhaps my anecdote is not as strong because I got locked out rather than blocked out, but it still was inconvenient. I degoogled my life some time ago, long en
by eks391 4y ago
Perhaps my anecdote is not as strong because I got locked out rather than blocked out, but it still was inconvenient. I degoogled my life some time ago, long enough to have a new phone and computer. At a point I needed to log into my old gmail acct, and I couldn't because it was a new device, the old devices were gone to verify my identity, and knowing my password and passing several captchas wasn't enough. Months later I went to log into fb/ig for something and similarly wasn't allowed in and also don't have access to my gmail for verification. Luckily during my degoogling adventure, I had changed the email for all important accts, so the impact is minimal, but I would not like to imagine the impact if I had ever relied on oAuth
- knaik94 4y agoI feel a little more comfortable relying on oAuth because I have my 2FA secrets backed up. This story does make me reconsider and want to revisit how I manage certain services. I don't know if there's a reasonable self hosted alternative to all the google services I use. I even have a Google Voice account I've had for over 12 years now, I feel like that'd help if I ever do get locked out. I try my best to practice good account security hygiene. I already have multiple backup accounts, for email but also in terms of recovery emails for third party accounts too. But I appreciate your story.
- jefftk 4y ago> the old devices were gone to verify my identity Do you mean you had a phone number configured in the account but it was out of date, or something else?
- eks391 4y agoI mean the devices themselves. When you visit a site, details about your device are sent to the webserver, such as screen dimentions and resolution, processors, gyroscope information (orientation of screen), location, default language, and more, so the website can cater to you - rendering it to a good fit for your screen, using a protocol that works with your GPU, with relevant ads, etc. This data is called your digital fingerprint. Companies that deal with high security data (banks), advertising profiles (google), or bot abuse (everyone), will store the fingerprints to every device used by you on their webservers, so they know if it is a new device and to throw a captcha, 2FA, etc. I refuse to give out my number to most sites, which is sometimes the only 2FA option, so for most of my stuff, I just don't use 2FA. Despite knowing my password and passing 5+ captchas, having a different fingerprint and not having 2FA was too much for gmail and it decided I was still not verifiable. Idk if they decided I was a user in constant attack or something, but even when I had the old laptop they were always slow to accept that I must be me, making me fill capchas everytime and reinput my password.
- jefftk 4y agoThanks! Were you able to get back in by trying again after some time had passed, or was the lockout permanent?
- eks391 4y agoI just realized you are the author! That explains your curiousity, and I'll get into the nitty gritty details. A part of my previous comment isn't clear: when I say I didnt have 2FA, I meant I didnt have it enabled at all, not that I had it enabled and lost access to it. Also I was thinking about it more, why google was always suspicious of my log ins, even before I was locked out. I remembered that my settings back then deleted cookies upon browser close, blocked 3rd party cookies and pixel trackers, but because my fingerprint matched, it appeared to google that I was on a different but similar device at every log in. When you know you password, pass the captcha, but google still doesn't trust you and you don't have 2FA, google pings every device you have that is signed into it that is on, asking you to verify that you are trying to log in on a different device. I know this well because I had to click "Yes, it's me" on my phone every time I logged into any google service on my old laptop. So that's what I meant when I didn't have my devices to confirm me. It's googles 2FA for people who don't enable it. When I degoogled, I stayed that way even till I had replaced my phone (same cell #, new device, not signed into any google service) and so google didn't recognize anything, couldn't ping me, and so it decided to just not let me in. To your question about getting back on, yes. It was awhile ago so idr what I did, but if I had to guess, I used a family members laptop that I used at some point so it had the fingerprint and cookies, and I had my password am the ability to pass captcha. Then I could verify my new laptop from there. Google still has trust issues with my laptop now that I'm even more locked down on website/browser permissions, so I have another browser with custom settings that I use so google doesn't get upset and lets me use their services when I occassionally need them. They still don't have my number and never signed into from my phone. Btw I like your article. I think you provided good tips for the causal internet user. I am curious when the day will come when phishers spoof the oAuth though. Personally I believe in security through obscurity, but to be obscure also means there can't be a streamline solution. So whatever fits each persons needs I guess.
- jefftk 4y agoThe question of how large the risk is that Google or whoever you pick for SSO will lock you out over some misunderstanding around TOS is the main one I see upthread, and is pretty tricky. I'm working on follow-up post that gets into this question. I think avoiding the situation you ran into, however, is a very different question. How likely you are to get locked out for security reasons depends a lot on what security configuration you choose. The big risk here is that you set up 2FA and then lose access to your second factor. If someone were to follow the approach I advocate in the post, of always maintaining three registered security keys and adding a new one if you lose an old one, I think the risk of a security lockout ends up being super low.