It worries me, though, that they're willing to accommodate novices to such a degree that they open up advanced users to targeted attacks. For example, Gmail bugs you quite a bit to set a "recovery phone number," but doesn't make it clear that this isn't like 2-factor auth. The phone number is actually a single factor that can be used to reset your password. It even works if you have "traditional" 2-factor enabled.
Thus, the attack looks like this:
1. Look up target's social security number. This is easy with certain online services that were meant for private investigators, but actually let anyone get an account.
2. Contact their cell phone provider. If you don't know which one, guess. There are only a handful of common providers and you'll hit on it eventually. Impersonate the target, say you're going on vacation and need your calls and texts forwarded, and give them the SSN from step 1 to verify.
3. Go to Gmail and say you forgot your password. Opt for the phone based reset, and wait for the text with a reset token to come in. Ideally, do this while the target is asleep to give yourself time to work.
High profile individuals have actually been hit this way, and I think Gmail should offer greater protection to sophisticated users who do everything right, don't fall for phishing, and would never forget their password, but can fall victim to highly targeted attacks.