What would you do if you lost your Google account?
blog.viktomas.com
blog.viktomas.com
I operate on the realization that google will one day arbitrarily destroy my gmail account for absolutely no reason. At any time. Because. Due to reasons. Those reasons which include the knowledge I will likely never have anything clearly explained. Reasons I cannot appeal. At all.
This is what free gmail means to me. Same goes for youtube. Especially youtube. Videos can be deleted for no reason. Better keep copies.
Famous people have lost content on google and youtube. Blocked emails. Lost videos. etc etc. I'm a nobody. If famous, "important" people have their accounts "accidentally" deleted, what hope do I have? None whatsoever.
I have no idea what google would be like for paid accounts of my own but I was working with a company that did and the support wasn't terribly helpful during a email migration so I'm unimpressed. At least they responded to my emails after a few days.
For example, they probably get thousands of requests for account assistance. But they have full access to the emails in the account. And related metadata like age of account, volume of emails, other services used (Android apps released, Youtube videos created), and others. It should be simple to create an algorithm to prioritize the requests. So if an account was created a week ago and doesn't have much history? Low priority. An account is 10+ years old and has regular bank statement emails incoming? Highest priority.
And if that's too much work, just provide a paid option. Tell users that if their issue is really important, then pay some amount (such as $50) to get immediate urgent support. The user with a one week old account won't care enough to pay. The spam scammers obviously won't pay. But the user with all bank accounts, brokerage accounts, other important services going through their gmail account? They will likely pay to get assistance.
Instead every account gets the same shitty treatment. They could easily identify the important accounts to look into first using data analysis and algorithms. They're supposed to be good at this stuff! Or provide a paid option. Or do both. Only explanation I can think of is that it doesn't look good enough for a promotion so nobody at Google cares.
1. My ad clicks went from a steady 500 a day to 1-5 a day and my revenues plummeted. I contacted Google. After one month of of being passed around they tell me they're not allowed to disclose what's wrong, but I can try labeling my ads as "Advertisements" on my site. One month of waiting for that response.
2. Recently Google started clawing back 50% of my monthly earnings at the end of the month. It's typically 0-10%. However, it just jumped to 50% the last couple of months. So they give me daily reports that I'm earning $150 per day, and then at the end of the month they just say nope, we're actually going to only give you half of that revenue. Oh, and we can't tell you why, that's confidential. I searched online and found lots of people recently reporting 30-80% of their revenues are being taken away. No one can get a reply from Google. What's even worse, I use header bidding. So someone opens my site, Google says they'll pay X to show an advertisement to that user, they outbid my other networks, and then a month later they say they can't actually pay that price. Meanwhile, my other ad networks could have shown an ad, but Google outbid them with a price they're not willing to pay.
3. I tried to setup an in house advertisement the other day using Google DoubleClick. The idea is that I create an ad for my Patreon page, and if none of the ad networks I run can pay more than X for that impression, then it shows my Patreon advertisement. Well, Google says Patreon is malvertising, and they won't let me run a display advertisement on my own site, linking to my own Patreon page. What does that notification say in the ad manager? It says they can't disclose any additional information and not to contact them.
This company is a joke. They've collected at least 100k in commission from me, and I get zero support. I'd like to fix that issue resulting in half of my revenue being taken away each month. Nope, no one I can talk with, and if I do talk with anyone, they can't disclose that information or what ad unit is the source of the issue. I need to try making a change, and then cross my fingers that one month later I don't lose most of my revenue. It would probably take a year to understand the issue with monthly experiments. Anyway, I'm in the process of removing Google from my life now. I have zero respect for that company.
I’ve had a gmail account since early beta. I upgraded to their $10 per month for 1 tb storage (which they recently increased to 2 tb). I recently got a better deal from Microsoft so want to switch. So over a week ago I deleted my entire Google Drive. Except it put everything into the Google Drive “trash” that still counts against me. I immediately emptied the trash except that literally did nothing that I could tell.
Then, about 100 GB per day has been freeing up from the trash for the last week and a half. I can’t cancel the extra storage until this is complete or I’ll stop receiving email on my gmail account. At the snail’s pace that it’s freeing up storage on my Google Drive from the trash they’ll be charging me another month. It’s ridiculous. And as a paying customer there’s no practical way to contact them.
I think this is the most troubling aspect of Google (free) services. This is why I bit the bullet a couple of years ago and started running my own mail server. The buck stops here :)
I pay for a personal google account there. It gives me the peace of mind everyone's talking about. And I get customer support when I need it.
No! We need to demand more from Google (or, at least our lawmakers). I have a business that relies on a Chrome extension to be on their web store.
Say I accidentally trip off something in their opaque machine learning algorithm that determines my extension (or even a YouTube comment!) breaks their terms of service. They would have the right to completely block my account and remove the extension. Effectively, wiping out how I make a living with a single automated bit flip.
It hasn't happened to me, but the people that share horror stories of how it happened to them scares the $#!7 out of me.
As the Internet gets more privatized and less "open", I just wish there was something that required a fair "trial" of my account being suspended. The balance of power online is slowly shifting and I feel there needs to be something protecting the rights of individuals (the public) online.
I wouldn't hold my breath. I encourage people to put their money where their mouth is. E.g., I host my email with Fastmail.com. is that free? No, and thank goodness.
Google's core business is selling your eyeballs to people who want to influence you. Their relationship to eyeball owners is statistical; as long as they are providing adequate quantities of wallet-connected eyeballs to the highest bidder, they do fine. This drives a fundamentally different culture than businesses that live and die by customer relationships. And culture is extremely hard to change.
I don't know Google's numbers offhand, but Twitter's revenue is about $1 per eyeball-pair per month, with per-user profit much lower. Think about your salary, and then think about how much work you'd be willing to do for a given account. By my numbers, handling one medium-sized customer service issue could easily wipe out an entire lifetime of profit.
And that's before we even get into the literal millions of scammers, jerks, loons, and mafiosi that would a) happily misuse a Google account, and b) will eagerly waste hours of customer service time lying up a storm. Every extra inch Google gives an actual well-intentioned user means a few hundred miles taken up by that lot. Which is expensive indeed.
So I am entirely grateful that I'm paying Fastmail $50/account/year. That builds a culture of wanting each customer to succeed. Of wanting customers to say good things to potential customers. Which means if that there's some bump in the relationship, they're going to at least hear me out. If you too want that, please pay people money for services.
And people will leave Google for another free email service if even a small percent of people begin to lose their accounts.
Google definitely has an incentive to keep email functional.
Demand all you want. Remember that you're not a customer, you're a user. Google offers their free services to keep you in their ecosystem, which allows them to collect more of your data and serve you more ads.
Users are much more disposable than paying customers. So what if they piss off a few users? As long as most people keep using Android, Chrome, Google Maps, Google search, YouTube, etc, there is no risk towards their bottom line.
Sure, you could try to go after them with government regulation, but they have tons of lobbying power. On top of that, even laws with the best intentions can often backfire and sometimes do more harm than good.
The only thing you can reasonably do is recognize your position and make sure you are never dependent on Google. You can still use Google services; just make sure you have a plan for when that suddenly stops being an option.
Even paying customers can be removed without trial.
Except some very few regulated things, no store has an obligation to carry this or that brand of product. Even in retail.
The way it works with Android apps is if some random code quality shell script of questionable quality flags your app, the app will be removed and you will get a lifetime developer ban from Google. There is no human in the loop and no appeals process.
Because there's a monopoly for Android apps, there is no reason for them to ever improve customer/developer service.
An excellent analogy would be getting banned for life by a programmers union if anything you write ever fails a valgrind test. Doesn't matter if its a bug in that revision of the valgrind test and there will never be any human contact in the process.
"I've been banned from google and I don't even know why" is a weekly discussion topic on android development forums.
Even funnier is Google implements guilt by association. So if you have a similar email address or ip address to someone who gets banned, the same shell scripts will lifetime ban your account under their ban evasion policy.
Your comparison of Google Play being like a normal store, would then make Android the town the store is in.
Would your position be that Walmart should be allowed to pay off the town to prevent Kroger from opening?
I hope we get to the point where something in the commons (government or whatever), can offer comparable assurances about digital things that are becoming critical infrastructure in our lives
Welcome to the new old world. :(
No, you should operate on the basis that google can stop doing business with you for anytime for any reason and make plan accordingly.
If there is any need, it is from your government (wherever it is) to go break the Google self-supporting monopolies.
You can try to demand that a private company offers you high quality service for free, but I wouldn't recommend wasting your time. Alternatively, you can try to use other services, but again, those multiple self-reinforcing monopolies are an issue.
This sounds very much like the old-world Christian conception of "acts of God" re: natural disasters and the like.
The Catholic Church has the concept of saints, highly placed people that intercede with God on behalf of common people. For dealing with Google, modern people petition "influencers"
You're dead right. So now, in addition to trying to exercise every day, and unpack another box from moving every day, I'm committing to moving one account email to Fastmail every day.
Famous people have lost content on google and youtube. Blocked emails. Lost videos. etc etc. I'm a nobody. If famous, "important" people have their accounts "accidentally" deleted
There have been far too many incidents where people who become virally infamous immediately have their accounts blocked or deleted mysteriously, followed by having them restored with no explanation. This indicates that Google/YouTube employs people who will arbitrarily abuse their power in the control of these valuable and highly private information resources, over whom Google/YouTube has too little actual control of oversight.
Downvotable Material: There's a certain billionaire who wants to privatize the right to travel through a certain "passport" he's advocating. Will they just be able to turn you off and there will only be non-existent or unresponsive customer service that will just tell you that there are "reasons" why you're not in the system any more and they are a private company and can do whatever they want and buying their product is optional, when it really isn't. Hopefully, if this ever comes to pass, there will be extensive regulatory legislation like the Fair Credit Reporting Act to keep this sort of thing subject to due process and transparency. The global nature of this "passport" means that when in foreign countries with weak judicial systems they might still be able to arbitrarily terminate your account.
I would add (free) Github to that list.
I think there were OneDrive-triggered killing spree at some point when they made backup to it more or less silent and offended by what people were “uploading to website”
This is an important number. 1% annual chance? bad deal. 0.01% annual chance? Maybe worth the risk. 0.0001%? Sure, I'm more likely to get hit by lightning.
Not sure how to judge the annual risk, but there seem to be a lot of other stories like this.
I prefer to think of it in terms of "nines" of reliability. My account was "up" pretty continuously for maybe eight years. It's been "down" continuously for four years plus the next thirty-plus that I might need it. So, a total downtime of 0.81. Being charitable, I'll call that one "nine".
Nowhere in tech would that be considered acceptable.
This is exactly the argument that android/ios apps, google accounts etc, is it optional or not. I couldn't go to the gym where I paid in advance because I didn't have supported phone (latest android or ios). You'll always have a choice right, now it's the choice to wash your clothes by hand. Who knows next time you might not get an apartment without a gov approved android/ios app on your phone, it's a brave good old world again.
Q: Wouldn't it be better to pay a small amount to $anyoneOtherThanGoogle ?
Had it for a few years back then and never did anything bad or oblique with it, just used it as my secondary email account and also for deploying a small, harmless Chrome extension to the Chrome store.
So one day my wife bought a tablet and also registered a mandatory account. 1-2 days later my and her Google account was terminated. I mailed support and they told me they couldn't tell me the reason for terminating both accounts. No kidding. Tablet suddenly obsolete. All my emails gone.
Since then Google is a big red flag for me.
Addendum to clarify: They said they won't tell me the reason for terminating my account. I'm sure they could have told me if they wanted to.
Somebody (presumed ex- or current-employee) took handful of iOS devices from our office a few months ago. Changed the password to the Apple ID, added 2FA phone number.
The account isn't even deleted, and we can't get back into it.
We have a dozen other devices logged into that Apple ID, all prompting for the password. You cannot install updates, you cannot roll back, you cannot log out, you cannot factory reset.
Apple have been no help at all.
The devices we have that are logged into this account are bricks. Apparently if we have original proof of purchase, we can take them into an Apple store and have it reset. But a lot of our devices are older or were acquired refurb/used - they're used as testing devices.
The accounts are locked, they just won't help us get back in, we've tried several times and channels. We've offered to do anything, sign anything, they won't do it. I once went through password/2FA recovery with an Amazon AWS account, and it really wasn't that painless (sign some legal paperwork, show a bunch of documents).
We are an unknown startup, but we have generated millions of dollars for Apple over the past decade in App Store cuts. If we can't get back in, I don't know how it'd go for grandma's iPhone.
after 4.4 they dialled it back to instead of required now they only apply some seven dark patterns to try to trick users into thinking it is mandatory.
same effect to most users, zero regulatory consequences
Low level random tech-support? Probably not.
One day I couldn't login anymore to the old account (maybe I typed the wrong password 3 times or maybe it was deemed inactive because I would never login?)
I try the recovery process once in a while with everything (code by SMS, code by recovery email, etc). Never works.
But I still receive every email sent to that account through the "forward everything" setup from XX years ago.
Further note that gMail filters at every step, eg this includes a downstream "archive" account. So there are false positives coming from a "known" [single source] good account and of already vetted emails...
i do wish there was a way to forward everything ... where everything meant everything ... filtering optional.
See https://cmetcalfe.ca/blog/forwarding-spam-with-gmail.html
Every few months, I try the recovery process again to no avail. "Sign-in with Google" is very convenient so it'll be a pain to move to proton + outlook but c'est la vie
I can confirm it works as well since someone sometimes fat fingers whatever email address they use for car repair and I get the invoice for it due to Google not respecting the dots in the email address.
My master plan is to get hired at gmail just so I can click the admin reset password button and get access to that account directly so I can finally see the very first emails I ever received.
I never use Google to login anywhere anymore. I create an email and an (autogenerated secure) password everywhere. If they don't see fit to support this, they don't get my business.
Then I just let Bitwarden/Firefox take care of everything. Logins, etc. I have 500? passwords stored. Don't know any of them. I prefer it this way.
I've got an old gmail address with pop3 enabled that my main gmail account pulls emails out of. Hadn't logged into the old address in a couple years because everything was working. One day I decided to rotate all of my passwords, got to that old gmail account and it refused to let me log in and wouldn't say why.
"No big deal" I thought, I use a password manager, have all historical passwords, have the 2fa device, same phone number, same address, I have access to the recovery email address, and pop3 still works so I know I have the current credentials. I'll just reset the password.
Nope, wrong. Even though I have every possible form of identification the account will not let me log in via the web interface and will not let me reset the password. I get stuck in a loop that eventually ends with "Thanks for verifying your email. Google couldn't verify that example@gmail.com belongs to you."
The pop3 functionality still works, but the password can never be reset and the web interface can never be logged into. I suppose this will continue until the day google decides to ax pop3 and imap, no doubt accompanied by a blog post with comments disabled explaining it's for our own good, at which point that address will be lost to the sands of time.
I wasn't sure whether I should set up forwarding on my Gmail account or have the server fetch mail from it regularly. Was leaning towards the second option but I think now it's settled which option to choose.
Edit: Ok there's one more stupid scenario. Let's assume I do lose access to the Gmail account but forwarding still works. Now I'm in an accident and stay at a hospital and totally forget to pay the renewal fee for my domain. Boom, some domain squatter gets all my mails. Actually, that would even apply without Gmail in the mix. Sure I'd set up automatic payment for renewal but still, can I be a little paranoid here? ;-)
If you're in a 9/10 year coma, you probably don't care about your email any more.
Don't do this. Buy an email with a domain that offers email. e.g. gandi.net or infomaniak.com They do have phone numbers if things go wrong. Hosting your email is easy. Having you emails delivered and not blocked is an art.
Who knows... maybe someone else recovered it that he's using it as their primary address and I'm just getting copies of all their messages?
Very similar to how a phone-sim has kinda become the de-facto digital ID of most people.
In the long term, where does that leave people who can't afford a mobile phone/a paid e-mail account?
This is already somewhat of an issue with certain digital services that won't accept e-mail accounts from free providers that are too abused for spam.
What happens to the people who can't afford a paid e-mail account when billing and so many other services are moving to digital heavily depending on the availability of e-mail?
In contrast to that, I don't have to pay a monthly fee to have a physical mailbox at my door, but that won't get me far with most digital services.
Sure you do: it's either rent or city taxes. The fact that the mailbox comes bundled shouldn't blind you to the reality that you (1) do pay for it, and (2) many people lose access to that address due to inability to keep paying, and it heavily harms them.
An email address is comparatively way more easy to maintain, even with the occasional Gmail account closure (which are rare).
My patient base includes a fairly large homeless cohort. They maintain email addresses; some of them maintain phones. But a physical mailing address is basically unattainable.
As far as standards go, E-Mail is pretty much one of the more, if not most, open ones out there. You can easily host your own server. The RFCs are free to read and there are many open source solutions doing the hard work for you. Sure, there are problems with spam defenses and acceptance from residential IPs, but overall it's one of the few meshed standards left. And it's nearly impossible to get it any more free; after all, there are many privacy-focused GMail alternatives (i.e. Protonmail) which work just as well.
And let's be honest - if we'd be replacing mails, we wouldn't get something better. It would be more like "login via Google/Facebook". I'm really happy E-Mail is still alive.
It should be seen as a "hidden cost" to any digital service that requires an email address (either monetary for a trustworthy enough email account or in the form of privacy).
As an aside, this sort of forcing people into using digital services with terms they don't agree with has become widespread during the pandemic and it kinda makes me angry how no one is thinking about any of this.
> What happens to the people who can't afford a paid e-mail account when billing and so many other services are moving to digital heavily depending on the availability of e-mail?
Unless things change a lot, any company that wants the general public's business will accept free email accounts.
The same goes for why every company already requires an email address at all - their target market is anyone with internet (excludes 10% +-1% [0] of the United States) that can create an account with Apple, Google, Yahoo, or Microsoft.
0: https://www.pewresearch.org/fact-tank/2019/04/22/some-americ...
Email addresses are just the internet avatar of the problem.
So because their authentication used some stupid heuristic combined with the “no reusing old passwords” thing I was forcibly deplatformed. I’m not making another account, I already wasn’t happy with google and that was enough to make me give them up.
Honestly, it's a huge relief. Self-hosting has gotten much more complicated over the years. It's very nice to know that there's a round-the-clock staff of professionals taking care of security, deliverability, and fighting spam. And software upgrades, of course!
It's been few years. I am on Mailbox's 12 Euro/year plan which has "forum" only support (I am not sure it changed after I became a customer). My emails suddenly stopped working once and I received email response after a week (which just had an irrelevant link). I had reset the mail setup by then after backing up email from local client. I replied to the email asking what went wrong and never received a reply. They seem very aloof and high-handed about customer support if I may say so.
I am looking at moving my mail provider. I have stopped using @mailbox.org mail for online a/c signups etc (which I did a lot earlier) and have started removing it from wherever it is used already.
Is Migadu stable and been around? How's their service and privacy track record? Did you evaluate any other provider in Euro 12-20/year budget range? My email usage is extremely low volume.
I've tried to set up contingency plans for the cases that I lose access to my:
- phone (which contains Google Authenticator with plenty of important logins; unfortunately some of my 2FA is still based on SMS)
- my laptop
- my Yubikey
- my wallet (with ids and a credit card)
due to theft, damage (house burns down) or simply loss.
Another under-appreciated risk: losing my memory (my master passwords are only in my mind - what happens if suffer a head injury and forget?)
Redundancy is one countermeasure: Have more than one bank account + stock portfolio, more than one credit card (servers might go down if a credit card is blocked) and physical devices (phone, laptop) in store to stay operational in case of an emergency.
Full machine backups + regular uploads "to the cloud" for raw data; occasional transfers to (multiple) external hard drives.
I don't think there is a way around a safe physical space with printed backup codes on it. Ideally not in the same house - maybe with a bank?
A list of instructions for numbers to call for account recovery or blocking. Which information will I have to provide?
In a similar vein: what happens to my data after I die? How would my (non-technical) family be able to access my pictures and writings? A digital inheritance would be prevented in my security set if I don't prepare.
This space is fascinating to explore, the zeros and ones people have stored on their devices are incredibly valuable to them and this treasure is poorly protected. Generally speaking: No backups, weak passwords, outdated software, old hard drives ... risks abound
Google surely has very capable security people, but right now my account there is the central vector of attack, most of my passwords can be reset through my email, a huge portion of my communication runs through Gmail, Whatsapp is backed up to my Drive, most of my pictures are on Google. It's probably a good idea to disentangle the situation a bit to be prepared for the case that Google's fortress gets breached one day.
Without compromising your security - I'd love to know how others approach their personal IT security challenges?
Most of my security is based on OpenPGP keys stored on a Yubikey. In case the first one is broken/lost I've got another one. If both are lost there is a master copy on an offline computer that can be used to provision more Yubikeys.
The key unlocks access to passwords stored in pass. Because pass is based on git and gpg can be used to access SSH then the same yubikey is used to pull/push changes to pass and read encrypted passwords. On both the laptop and the phone (Password Store).
Data on the computer is LUKS-encrypted, unlocked by the Yubikey. Full backup of my laptop's SSD is done via btrfs send/receive to a raid1 array of 3 disks (raid1c3) on a regular intervals. A small subset if very important data (documents) is also backed up via restic to S3 and Backblaze.
I try to "backup" as much of my work as possible by releasing it as open-source (where it's preserved by the Github etc.) or publishing it on a web-site (where it's preserved by archive.org).
> In a similar vein: what happens to my data after I die? How would my (non-technical) family be able to access my pictures and writings? A digital inheritance would be prevented in my security set if I don't prepare.
I've been thinking about this lately and maybe it's not a popular opinion but... would people really need your data when you die? I get access to photos (my SO has the PIN code) but everything else? Maybe this is just digital junk? Who would enjoy browsing terabytes of my data looking for... what exactly?
:( I have set my gmail to be destroyed if not used for 3 months.
I might be paranoid but with clouds I would be more comfortable with AES-256. If RSA is a must, maybe RSA 7680.
Not just a head injury, this can easily happen if you find your keychain 10 or 20 years later. I don't think that there is a good solution to it. Maybe biometric data, but then again, I want to have a control over when my data is accessed and in many countries it's legal for law enforcement to make you use your finger or face..
There is. Put it on a piece of paper in a safe place.
Maybe write down my master password and put it in a safe?
Phone broke and I must have typo while doing a regular password change - now I have no way to again log into my account as i can't provide the 2FA and none of the other options work (providing old contact emails, phone code, backup email, ... All doesn't matter just because I don't have the authenticator).
- I need to migrate away from SMS based 2FA
- then away from Google Authenticator
- and probably also from LastPass to Bitwarden
[0] https://www.wired.com/story/a-sons-race-to-give-his-dying-fa...
It does not have to be fort knox safe, enough if stored at a trusted place which has no direct relation with you (in my case it is my best friend I trust with my life)
Customers seem, if anything, more angry about that though...
Especially when that service is free and effectively anonymous, it's just not possible to give each case a full and fair hearing. You know that you'll get false negatives and false positives. You can try to minimize them, but actual justice is expensive. Too expensive to pay for with ad sales, that's for sure.
You never know when they change policies and some automated bot kills your account for it, years from now.
Tip 1b: Make sure your password manager isn't using your Google account for authentication. :)
Finally, spinning busy icon and... red text says you are denied. You are properly screwed.
(My experience a few years ago)
Don’t do this. It won’t do anything good and I also doubt some random googler has the privileges to restore your account. There are likely policies in place similar to how I am not allowed (or able) to touch our customers accounts
Source: firsthand experience. I had problems with Google Fi when it was pretty new. I tried to work through the issue with their normal support, unsuccessfully. I worked at Google back then, and eventually point filed a ticket with (or maybe emailed? I don't remember) the Project Fi team. Lo and behold, my issue got resolved almost immediately.
If you backup regularly, you should also restore to test it works properly, and the reality is there is no decent way to restore a google takeout archive to another google account, or any competing service. The closest you'll find is a hodgepodge of scripts to incompletely restore some data...
Technology isn't perfect so a backup is a must for anything of value: whether financial or sentimental. For a good example of why backups matter, look at the history of Doctor Who. They didn't leave any backups of parts of the original show because they figured those were pointless, re-recording on the physical copies instead. Now the old episodes of the show are being searched for across the Globe, I believe some were even found at some man's home in Brazil. Backups and archiving stuff is essential.
This is how I did that:
1. I self-host my email and most of my emails are exchanged via my self-hosted domain.
2. I use nextcloud for cloud storage with automatic upload of pictures, videos and call recordings from my phone.
3. I use ZFS for snapshotting and replication.
------
Regarding my google account... I took the habit of taking notes of my previous password when I change it with a new one. I also took note of my backup codes.
------
Regarding self-hosting email... It's surprisingly low-maintenance. My current mailserver was set up in 2014 and I've touched very little since then (considering it's been on for six years).
It does require some learning in the beginning, but a) email is so old that's very, very, very well documented and b) time spent learning is never wasted.
Nextcloud is just awesome. It does have its quirks and an SSD would definitely help, but I've been running it off a cheap machine (~115€ dell optiplex 7010, 2nd gen i5, 8gb ram, 250gb HDD system disk + 2TB HDD data disk) and only had occasional problems (don't try and push too much stuff at the same time or postgress will basically kill itself if it can't keep up -- upload files to the data folder instead and let nextcloud rescan such folder).
ZFS is the real game changer. Hourly snapshots are extremely fast and cheap and make it easy to sync your precious data to another location (in case something goes wrong).
------
Sometimes I stop and think about how exploitative and predatory modern internet services providers are.
Most TOSes clearly state that they can terminate your service for any reason. Which is generally understandable but also mean that all of your data could be gone so fast...
The cloud isn't really the safest thing to put your stuff into.
>Regarding self-hosting email... It's surprisingly low-maintenance. My current mailserver was set up in 2014 and I've touched very little since then (considering it's been on for six years).
What will you do when you're email server's OS goes out of support? (or if VPS, they upgrade from ovz6 to 7, or worse) Or if you can upgrade but the packages for your original install are slightly changed or not available on the new version? How did you store the email? Virtual users on disk with dovecot or the like? How will you port to a new OS environment when required?
It's isn't trivial. I'm in the same position having set up my personal mailserver in 2013 with very little maintenance since. But now the bill has come due with the need to upgrade OSes.
I'm planning full OS update and mailserver reinstall (I'll probably be switching to CentOS 8).
Regarding the downtime... Not a big deal either. I already have an mx backup host in place, along with (semi-automated) procedures to imports mails delivered to the mx-backup host into the mx-primary.
> It isn't trivial.
Well, it isn't super complicated either. It really depends on the degree/detail of your configuration. For the most parts you should be able to copy the old configuration files into the new postfix/dovecot installation and fix errors as they come up.
Problems may arise if you have non standard features and/or if you interface with other services.
For some reason, it won't let me in. I am pretty sure that I have the correct password (I use a very well-known wallet app), but it's entirely possible that I borked the process.
Google won't help me to unlock it. I have to use a gmail account (the one I set up) to get reminder links, and I can't figure out why it isn't honoring my secondary email account (my corporate email, which works fine).
It really isn't a big deal (to me). It prevents someone else from registering as my company. It does mean that I won't be doing any corporate business with Google, but that's fine. I don't write the kind of software that uses their services.
Hm. That probably means I have lost my Google account. The last time I logged in was in 2013.
Check your password here: https://haveibeenpwned.com/Passwords
For very old accounts, they'll normally force you to add a phone number or recovery email address though.
But on the flip side, these companies are incredibly paranoid and secretive with their own data. They all run their own mail internally and do not (in general) store sensitive data on each other's clouds.
I think this is super important for companies like, for example, Facebook and Uber, to maintain utter secrecy of their internal data, because they know they have a lot to hide.
Anyways, the vibe is "Trust us, but we won't trust you". Yuck.
There's very few big companies that are concerned about MS or Google stealing their data. That's a concern held mostly by random hackernews commenters.
Giving the drive to friends or family isn't viable either because I need to encrypt the data and need to store the keys somewhere. So the cloud, i.e. AWS, Azure, Backblaze, etc. is actually a pretty good place.
Of course a successful backup needs to be at least "3-2-1". Not "1" (Google Drive).
That's what I did for Drive, Photos and Gmail. I setup cron jobs to automatically pull everything from there and save it locally.
The only use I occasionally get out of it is a shared document with somebody.
Same with getting a new phone number
Unfortunately, it's not available for GSuite accounts. I suppose the rationale is that organizations don't have the same requirements as individuals, but that's not the only use case for GSuite : any individual (like me) who set up legacy GSuite to use GMail with a custom domain is out of luck.
Thankfully I rejected the opportunity to "date" Google when all my friends were jumping on that train many many years ago :)
One simply cannot not have a Google account when on Android.
Google Maps and Youtube even work, but I have no expectation of them continuing.
we don't use Google devices requiring Google account and pretty much no Google apps
Is there genuinely no solution to this?
These days, I doubt it would be as big of an issue to lack cell phone service, for me anyway. I can imagine lots of scenarios where cell service would stop working, and imagining those people effectively locked out of their account until the towers could be rebuilt or repaired makes me sad for them.
If they just stuck to requiring a very strong password and not letting anyone in without it, no exceptions, no ifs, no buts, I would still have that account.
Fortunately it was an old account I wasn't using anymore.
Just use one Google account per Google service, it's the safest way haha.
The drawback is that they only allow you to use "safe" (read Google made) apps.
Wasn't the case at the beginning, when you couldn't open your email in anything but Chrome on Desktop and Gmail app on a phone.
This is problematic if a system relies on your using it enough to be a proof of authentication.
I don't need desktop sync. I only use cloud storage to archive old files that I like to have around but never really access, such as rare CDs or records that I've ripped.
Any suggestions for an alternative? Hetzner storage box? Glacier? rsync.net? If only Dropbox had an intermediate tier...
There you can find some hints, e.g.:
SPF: PASS
DKIM: PASS
DMARC: PASS
If any of those are not in 'PASS', you need to fix it and retry.Yes, setting all of these up is not trivial, but it's also not the monster people usually claim it is and I think we should all do our part that this knowledge doesn't appear so unobtainable, as we're already centralized more of the internet than we should have.
* make sure that SPF is set on my DNS
* make sure that all my IP addresses (including IPv6) have correct reverse lookups
* enable opportunistic TLS support on postfix ("smtp_tls_security_level=may")
That last one made the difference for me, but I'd done the previous steps already so it could well require all of them.
I don’t care anymore, I’m done with google. Most large companies don’t use Gmail so it’s not really a problem.
Just because it’s not @gmail doesn’t mean they’re not using Google.
Just because the MX records for the domain don’t directly point to google doesn’t mean they’re not using google.
Check the headers for mail received to determine who they use for outbound mail. It’s usually (but not always) the same as the inbound path.
I never got closure on why, but I suspect it’s because I used my invitation links to create more accounts for myself.
What did I do? Tried to get an explanation, then tried to appeal, then set up my own mail server and have self hosted my own email ever since.
Should I even bother to keep reading?
I only remember one password, and that's the password to my password manager. The rest are arbitrary random strings. Always use MFA. I employ efforts to make it difficult for an attacker to port my phone number, too.
At this point in the maturity of the internet these measures should be a no brainer, but it's a good reminder of how far we have to go.
Writee is obviously NOT in Europe, where even to get a prepaid you need ID/passport. That way you can keep the same number forever (if you abide to the "add funds even X months). I have phone numbers in 4 countries (that I tend to visit 'often' and all I need to do is add €$£10 every six months to keep them alive.
So one solution for that is to go to that ISP of yours and ask them to bind your number with your ID. And if you lose the SIM one way or another, you show up with your ID/passport and in 10mins you walk out with the same number.
Doesn't that cause the opposite problem - for example, someone with access to your prepaid account could change that data and go clone your SIM?
The help pages are Ridiculously obtuse.
We use google maps for a non profit and they require a credit card. It’s was near impossible to figure out where to update. (Why not send a link in the email to where I needed to go?)
They really could Be so much more profitable If they could get there ui ducks in a row.
Also, for anyone thinking about giving up gmail: check out fastmail. I never regretted switching my email over to them.
Then my moment of dread came: the codes didn't work. I still don't know why but from that moment on the laptop I brought with me that had Google logged in was my only gateway to my personal info.
I mailed account support and after explaining the situation and providing proof they reset my 2FA, after which I could set it up again on my new phone.
Even though Google support was pretty quick and helped me out (in my own language, mailing from China) I have since moved to GMail with my own domain for more control, have printed out backup codes that I test every 3 months, have multiple phones with Google logged in for 2FA and periodically use the GDPR method to download stuff Google has on me, just to be safe.
It was an eye opener how vulnerable I was using Google's "one account to rule them all".
If you want to minimize or practically eliminate the Google account lock-out risk and also eliminate any hijacking risks, register multiple hardware security keys (FIDO keys), remove all phone-based 2nd factor or backup, and make sure your password is something you won't forget (it doesn't have to be very strong - as long as it's unique), and register for Google's Advanced Protection.
Because there is no known attack against hardware security keys, there has been no broad attack - which means heuristic-based defense is not necessary. The heuristic based defense is a necessary evil - it's the source of false positive lockouts, but necessary since otherwise credential stuffing attacks can't be controlled / reduced.
You want at least two security keys, preferably 3 (one with your primary device like laptop, one personally with you e.g. in your key ring, and one stored at home, preferably in a fire-proof safe - alternatively you can leave your security key at work if you're ok with that exposure). You really want redundancy - as much as you fear lock-out, you should never lose access to at least one of your security keys. If any of the security keys get stolen, you can immediately de-register and get a new one to replace it.
You want to get rid of SMS or phone-based 2nd factor, since phone hijacking is a realistic threat. You also don't want OTP as it's phishable, and is more difficult to maintain high availability (you lose one device you registered as OTP and you're doomed).
this happened on April 8th while I was sleeping (I received recovery emails etc -- everything was changed by the time I woke up)
this old account had an auto-forward for all emails to another email so for the first week whomever stole it was not aware everything was copied to my other account. I tried going through googles account recovery and unfortunately it appears that I will not be receiving this account back, I am sad because I did not copy all email locally and have lost some very old emails -- trhis account was made when gmail was still beta with an actual 'invite'.
what is surprising is how obviously it is fraud based on the emails I received over the next few days the owner had different names for a handful of people i.e. 'Hi Chinh' or 'hello Hau' (many others as well)
I kept these because apparently google is investigating and I've been told to be patient due to covid-19 delays but I suspect I got lost in the pile of other work. it is not a big deal in the long run just makes me sad that clearly I did not do enough to protect this account and there is not a human on my behalf looking... any person looking at this (if google admins can) would come to the very quick conclusion it is clear that it was stolen.
Of course now I need to not lose control of the domain, but that's something that can be solved with a calendar app or... a calendar.
I think this is a reliable approach, because if I ever lose control over the hosting service account, I can prove my identity through invoices that were generated along the way.
Is this a common approach if you loose access to your hosting?
All data on Google is backed up, and can easily be transitioned to another provider
I learned long ago to avoid vendor lockin, I go to great pains to ensure that in all aspects of my life
Has anyone reading HN developed a process/policy to cover disaster recovery in the event of SAAS (insolvency|malfeasance|ransomware|data center breach|corrupt backups|identity theft|ad nauseum)?
Even if there were a one-size-fits-all export automation platform (maybe there is, or there's Zapier ... please weigh in if there's a quality one stop shop), the format you get from most providers (IME) bears little resemblance to the ecosystem you exported it from.
You can't get back there from here, so to speak: a csv (or series of csvs) are missing the relationships needed to reconstruct complex data on the platform, assuming you'd risk returning.
Thanks for any thoughts.
My personal email is not on Gmail. My documents are not in Google Docs, my data is not in Google Drive. I upload my videos elsewhere. My browser history isn't in Chrome, etc.
While I understand the individual value of some of these services, personally I don't understand how people can put all of their eggs in one basket.
If you're afraid of Google banning you for no reason, and you should be, move to alternatives and I don't mean moving to another monopoly that can as easily disallow access to all of your data and online persona.
And make backups, for sure, but I don't think backups are sufficient, because it's costly and recovery from backups often fails, being a last resort hail marry solution.
What if you lost your 'XXXXX' account? In my very humble opinion, anything stored on the 'cloud' is lost already.
I got burned very early on, back in 2011, with 'cloud storage' while using a DropBox account. I then proceeded to be my own on-line storage server. I use my server (that's already running 24/7 anyway) to serve SSHFS, SSH, SHTML and FTP to myself and just SHTML to anybody else who may chance along. The server is UPS-protected.
And I don't have to pay out those everlasting monthly fees to some faceless company who doesn't care at all whether or not they happen to lose my stuff.
* utilize a known unique password + non-SMS based MFA and document the password and backup codes in my password manager
* pay for G Suite instead of free. I have been through “lost credential” scenarios with other Google customers and, though painful, you can regain access via proof of domain ownership
perhaps most importantly, I use my own domain
* I sync my photos with both iCloud and Google
* my files in Google Drive are backed up locally
There’s no way I’d rely on a free account or domain with anyone at this point for the majority of my digital life. There’s just too much pain involved with losing it and it’s too easy to prevent.
I'm interested in tech, software and, making things so an awful lot of the Google-prison is as uninviting as the Apple-prison. I only use the tools that give me the choice to use for no other reason than fit for purpose. So I had no YouTube, instagram, tumble, Facebook and a whole lot more. No loss and nothing missed whatsoever.
My advice is for all free services assume random removal. Prepare for that.
I wonder what happens with my Android devices. Reset to factory settings or is it possible to switch accounts? And what if they ban my phone number, is that even possible?
I have my email at my own domain for which I pay about $10/year, my phone runs LineageOS, and I back up all my important data between my various devices with Syncthing. I try my best to avoid giving up too much control over my life, especially when it's as easy as purchasing a domain, installing an operating system, or setting up an application. Altogether, these actions took about an hour or two to complete, and they'll likely save me so much more in the long run.
If I can do it, you can too!
Apply common sense and diversification. Use different services for your email, cloud storage, photos and videos. Have a backup of your every service - mirror of your cloud drive, reserve email, locally stored credentials in any offline password manager.
While I’d be sad to lose my Google Voice number in use since 2010; I’ve been using my iCloud account since the day it was launched as iTools. I have had my @mac.com email for 20 years.
Email is not much of a problem. The various email aliases all point to gmail, but this can be changed easily. sync's are done to thunderbird on Linux and Mac email. POP, not IMAP. IMAP alone would be a problem.
What I did then was to block most everything Google (less Youtube) and find working substitutes. It didn't hurt me for long, I routed-around it. After that, I was never hurt by any of their service-shutdowns, and they've earned my scorn in many new ways.
The cases we’ve seen since, where people get their Google accounts terminated without reason or appeal options, have only made me more adamant in my position of not entrusting Google with anything important.
So the only thing I’d lose that would bother me would be my YouTube subscriptions and watch-later list.
if you "buy" something you are not root on or cannot change the bootloader (and everything) on, you must expect it to stop working from day 1. To me, it would not make sense to pay for that.
lack of knowledge doesn't save you, after all.
Then its not 2 factor, is it?
I have several Google accounts, all for different purposes, but I don't use any of them much, and not for anything that is really important. Google can probably all trace them back to me if they want, but I like to separate the identities. I don't check the email for any of them.
My previous job had all its accounts via Google. It felt icky.
I could probably still login and change the e-mail. Luckily I have AndOTP which supports backing up your OTP keys. I have over 22 keys atm.
I would have to make a new one if you wanted to look at some age-rated YouTube videos. That's all. I never did go near the Google ecosystem, having had a taste of them early only for support on a real, "we paid for it" product.
Does anyone have an idea why they stopped developing it ?
Note that the takeout archive will most likely not contain your original images. Google photos deletes, and in some cases rewrites, the metadata in your files. It's much better to back up your photos and videos directly from your devices. I use Resilio Sync or SyncThing to do this automatically, and then use PhotoStructure to manage and view my photo and video library on my own hardware.
I also appreciate that they gave me a checkbox for "please don't use my family photos to train your algorithms" so I can opt out, Google does not give you the option, all your photos are theirs to train with.
Right now I can think of email and password managers, although email could be further split into the mailing service and the mailing address
If your bank collapses your money is insured to an amount of X.
If your password manager or mailing service collapses you are relying on their goodwill to announce early.
I don’t know but is there a legal basis to inherit email addresses? I doubt it except if you also own the domain
I would also appreciate some kind of officially vetted recommendation for what to do to keep risk low. Something easy to read that can be forwarded to friends and Family.
Internet Service Access has become such an important part of the economy and yet we rely on blogs or the occasional newspaper article telling us what to do.
One day something big might break and it will hurt the unprepared
but if I lost my Outlook account which I use for exchange calendar, contacts and email sync, calendar and contacts would be no problem since they are at any time offline in phone, so just need to be backed up and moved elsewhere, email would be bigger issue, I would need to notify my client company about using my new address and then somehow try to change email address and many services I used this email
I'd have to find a replacement for Google Maps and YouTube, but I guess I could just create a new account for that.
I use ProtonMail and iCloud for email and calendar respectively. DockDuckGo for search, Firefox for rendering web content.
I backup everything to multiple locations/services, so I'm not too worried about loosing access to things in general.
Guess the most annoying thing to loose access to would be Facebook as I have a few contacts on there that I wouldn't immediately know how else to contact, but I'm sure I'd find a way if I really had to.
Google has too many of its tentacles in my life.
I am not storing any data of mine with Google (or Apple or Microsoft).