When you get locked out of your Google account, what do you do? (2021)
linkedin.com
linkedin.com
Worryingly, after the whole ordeal the author still seems to choose to rely on their Google account now as much as before this all happened. It's kind of a miracle they got through to Google in the first place and it definitely won't happen again; it worries me that this post doesn't end with "and that's why I split my life across separate dedicated services". It feels like the author learned This One Cool Trick instead of the underlying lesson, which is that Google (or Apple, or Microsoft, or any big provider) cannot be trusted to not randomly cut you off without warning.
My answer to this is that I've completely moved off of Google except for an account I use for YouTube/Maps access that I could painlessly lose.
Interestingly, I remember creating a new Google account a couple of years ago from the Philippines, without a VPN, and when I moved back to the US I couldn’t access it anymore.
I believe the account’s age has something to do with the restrictions.
I don't get how that can possibly be a requirement. I mean, it's trivial to dream up a scenario where it is 100% legit to be in this situation.
What is wrong with Google?
They made a rational 80/20 decision and then got insulated from feedback on the 20.
There should always be a break-glass. That break-glass should not be tied to a piece of hardware. That's why I don't use 2FA unless there are break-glass OTP, or I can use a generic authenticator. Authy, for example, allows me to install 2FA on my phones and desktop - no need to worry about losing my phone meaning I can't get into my accounts.
My bank on the other hand, uses Symantec VIP, which has no backup or break-glass. So my bank (the only one offering 2FA) is 1FA.
Authy is a great option but annoyingly it's tied to your phone number rather than a username, so you can lose access to that if you break your phone in a place where you can't easily get a new SIM card (i.e. if you're on holiday). You also need to remember to actually enable multi device in the settings, as it's off by default. It's a good service, but it's not without its own pitfalls.
I'm always wary of custom 2FA systems that banks and governments like to use, especially if they do nothing to actually avoid phishing. If you're going to make your own version of TOTP, at least solve the biggest problems TOTP faces. For this reason I like to configure krypt.co as my primary 2FA method (for as long as that's kept running) with TOTP (and optionally device-local webauthn) as a backup solution.
To get someone able to actually make decisions, especially when they are against a measure the system automatically put in place following its programmed or AI-.derived rules, you need to go at least two levels higher. Even "managers" often - usually? - only have digression within pre-determined possibilities and scenarios.
It's going to be like this: https://twitter.com/cnbc/status/1447916881009127430
I'm not enough of an influencer to get my rants here noticed.
It all comes down to which direction, and how much, the money is flowing with them.
According to this article being a Google One member didn't help them.
edit: As people are pointing out below, however, is there no way to use Google One support if you are locked out of your account?
There are no good answers here. A lot of things that work as one-offs or rarities will stop working if everyone does them. If there's a FCC form you can file that short-circuits Google's current process, and it becomes popular, that form is going to stop working. Restoring your access to a locked account is simply less important than ensuring strangers can't "restore" access to your account.
Obviously, one good change Google could make here would be to refuse to accept Google Voice numbers as an authentication factor.
There have been complaints after complaints about people being locked out of accounts, and there are no easy ways to recover - often no way at all.
To say that the paid support you're paying for can't help you access the service you're paying for, that's a bit rich.
> Restoring your access to a locked account is simply less important than ensuring strangers can't "restore" access to your account.
That's a false dichotomy. If you can pay, say, $200, and get 30 minutes with a tech who has access to your email and can go through a manual, interactive process to verify you are who you say you are - for example, if you can prove you hold the credit card that's been used to pay for Google One for the past couple of years - well, these "strangers" are going to have to work REALLY hard to "restore" their access to your account. Probably well more than $200 and more than it costs to install a keylogger and sniff your password anyway.
Think through what you'd hope Google would be able to do here. How do they authorize the request to unlock the account? Now imagine a well-funded adversary that knows exactly how Google's processes work (probably because they continuously pay for accounts and have them reset, to track what Google's doing). What's the reliable signal Google can use here, one the majority of their users actually have access to, that they can quickly execute on?
There are companies that have relatively quick Account Recovery processes through customer support. But those companies either aren't worth defrauding, or are regularly but quietly defrauded.
Remember, this is the most valuable account most people possess.
Nothing? Google sends postcards to verify business addresses already. If it's good enough for the bank to send me a card and PIN via post it should be good enough for Google. We have laws in place to deal with estranged spouses breaking into accounts.
A well funded adversary WILL take over your Google account. They'll do it by installing a keylogger and stealing your cookies, they'll do it because they know what signals the account recovery process is looking for - much better than you do, they'll do it because hacking you is far easier than hacking Google. (Two-factor authentication done properly, with printed backup codes in a safe location, can prevent hijacking most of the time.)
Second, Google accounts constantly do get hijacked every day. This draconian status quo might have been justified if it would prevent all hijackings, but it doesn't.
Third, my Google account is not my most important account. My bank account and portfolio which hold my life savings are arguably more important. But somehow I'm not worried at all about losing access to them.
Again, no system is perfect and it's mathematically impossible to identify the correct person for every account. But I still believe you can get the same false positive and false negative ratios without getting blog post after blog post from people who are completely stuck.
My point is different. Recovery is the hardest problem in authentication, but when you're as big and as significant as Google is, you owe it to your users, paying or not, to get it right, however hard it is.
There's a single potential client (maybe two if you add Facebook) who seems to be showing no interest in getting it right. Not the best business proposition.
But the account recovery problem facing Netflix or Github is different from the one facing smaller companies which is different from the one facing Google. I honestly doubt there is a one-size-fits-all solution, I definitely don't have it, but I'd be happy to be surprised.
In any case, lacking that, one could just walk into a Google office with a passport there. There are official ways to do authentication if these corporations really cared.
It's not rocket science. All banks can do it. It's just a tiny bit more expensive than saying "fuck you" to 0.1% of your customers.
My friend needed to respond to some interview scheduling, so, it was a stressful situation.
Part of the problem was that it was hard for my friend to find a way to create a support ticket. He did in the end and got in a line of communication via an alternate email.
There were many miscommunications from both my friend and the support agent. While Account Recovery or even basic identification are hard to navigate for technically-minded folks, it's even more challenging for non-technical folks, including the support agent.
In the end, I got in touch with the support person, helped translate what they wanted to know to my friend, and likewise, translated what my friend was saying in a way that the support person could understand.
I don't think I was able to see the support ticket itself, because of PII restrictions. In the end, my friend was able to restore service. I doubt he'd have been able to without my support in time to respond to the interview scheduling.
It still took a couple of days.
It is the reason why I have transitioned from Google.
Also wouldn’t backup codes help in this scenario?
Given that I pay them money, I figure they’re at least somewhat invested in keeping me happy as a customer. Google clearly don’t give a shit.
I did it last week. I signed up for Fastmail, followed their excellent documentation, and now only have a mandatory (new) Google account for a few apps in the Play Store that are not available anywhere else (but nothing paid). If I lose access to my Google account, I lose nothing.
My Fastmail migration basically went like this:
* Clean up mailbox, truncate mailing list folders.
* Copy mail to Fastmail using their importer.
* Change domain settings at your domain host (changing MX-records and a bunch of others); mail now goes to Fastmail.
* Set up mail and calendars in Thunderbird on Ubuntu and K-9 Mail on GrapheneOS.
After migrating an account, they know it, as they can scan your mail. Slowly, each red mark on your dashboard gets replaced with a green mark.
1. (Optional) Register a domain (So if you need to migrate in the future, you don't need to change your email address!)
2. Sign up for paid service somewhere else. Paid email services are extremely cheap, and worth it to have a phone number where you can call a real human person.
* If you wish to continue using the Gmail interface, skip step 3 *
3. Forward Gmail to the new account.
4. As you see messages you want coming to your Gmail account, switch them to your new account.
5. (Optional) If you really like the Gmail interface, use IMAP/SMTP to check your email in Gmail, even though it's really coming from/to your external account!
It's really easy to get away from GMail, and definitely worth it.
1. If your registrar account is compromised, someone can redirect your mail at will.
2. If your payment lapses you might lose the entire domain.
3. If you die, it’s unlikely your family will understand how to maintain the system.
4. Some systems will classify your email as spam even with the right MX configuration (DMARC,DKIM etc)
I think the right choice is having a paid relationship with a mail provider that’s been in the business a long time, and use their domain.
As for 3, well, I really don't care in the least what happens after I die. I won't be around anymore.
I can't really speak about how much of a problem 4 is, because it's never happened to me. I suspect the people who get their email classified as spam while using a large email provider actually are doing something wrong.
I know it happens to me, because I have to verbally follow-up sometimes.
The only way you would know if #4 doesn't happen to you, is if you're doing something wrong, like trying to track when people open the email.
I have three email accounts outside of gmail that are forwarding to gmail so I can have a favicon counter. Those email accounts maintain their own copies of the emails. If gmail were to lock me out I would lose my favicon counter. I would need to get a new phone number to create a new account and set up the fowards to the new address.
Why do I insist on this convoluted setup? My previous email client was a firefox addon that showed me that counter and it made me read my emails. Every email account that doesn't follow this set up that I have has lots of unread emails.
I have a thunderbird instance with 140 unread emails open right now. I have 0 on gmail.
As soon as anyone besides Gmail can successfully do spam filtering, I'm stuck with them.
(Why do I get so much spam? Because I've been using the same email address, never hiding it at all even on Usenet, for 25 years.)
The issue is trying to use multiple accounts as a kind of loss mitigation strategy. If Google knows about your multiple accounts, and one of them gets banned, they're _all_ at risk of getting banned just for being associated with the one.
It might seem hyperbole but it isn’t. Who is to say it hasn’t already happened?
If your livelihood is tied to your email / phone, then you really should consider a company with which you can communicate.
Accidentally apt malapropism/typo? They keep alluding to the idea that there may be something that can be done, but it remains illusive. :)
1. Containing or characterized by indirect references.
2. Figurative; symbolical.
3. Having reference to something not fully expressed; containing an allusion.
4. Containing or making use of indirect references or hints.
5. characterized by indirect references
Sounds about right for Google tech support really. I'll allow it.
They also have a separate site / login / forum for proposing new ideas, bugs, etc etc that you can use if you have an actual corporate account (strangely it requires creating a separate login and password). I have found that using this forum you can also get some decent support for weird issues or bugs or suggestions (sometimes from other users as well).
associate a VIOP number with your google sphere, so when it happens, file an FCC complaint re undue termination of telephonic service.
it seems this was the only thing that elicited a proper response. reading the article and google response to FCC complaint makes it evident, that google is full of it as far as "we cant do anything about it" is concerned.
the only problem i see is that it seems the complaint was dropped or left orphan, rather than followed up on. thats why google keeps on doing it because there are no real consequences other than being told to Give it Back.
it reminds me of when one kid swipes a toy out of anothers hands and keeps doing it because there is no real deterrent in play.
dont drop your FCC complaint, follow up on it.
After the response, the best thing would be to sue Google, of course. Not once, Not for big values. One small cause for each small annoyance. Not at the same time nor the same jurisdiction. Then read all the defences they make and mix then among the causes. If their system is so fragmented that they can't deal with your original problem of losing acess to your account, so they'll have trouble finding the pieces to defend themselves. And if they can find, even better, use it as a proof that they can connect the dots when they want to.
IANALITUSOA
"has to be" burns. It could be different. Why is a script essential? These support scripts drive me crazy. I would probably melt down in the OP's case.
Answers like "they allow less skilled first line workers" don't count because one could hire skillful people to solve problems on first contact.
My elderly parents were on google forever. Forgot password because they'd just stayed logged in.
What was weird is even though they had a recovery email (mine) that we were able to get a code too google had a second check - a requirement to TEXT a code to the phone number on the account. Unfortunately my elderly parents had put a landline phone down - which doesn't accept text messages.
I gave google the benefit of the doubt on that, because they'd actually forgotten the password.
More seriously, I was doing an apps setup (way way back) for a nonprofit. They give you a weird temp email domain, then you port in your domain etc etc. Some issue (no fault of ours) got the state stuck in a doomloop. Even though it was a paid service, there was no support.
I contrast that with AWS. Fine support on store side and on compute side in my experience.
As a bonus, Workspace is sold by partners, so you contact actual humans if Google does anything weird.
He was a bit put off by getting my rando phone call, but I explained my predicament and he took the time to look into it and helped get my account restored. Thanks Google engineer guy!
This probably doesn't work in 2022 though. ;-)
I've already migrated everything (mail, chat, storage, ...) to a self hosted server at home, but I can't delete my Google account because I paid 25 $ for the Google Play developer account, and I don't want to lose access to that.
Is there any way to use the developer account without a Google account?
There are enough comments about Google supports, so I won't comment on that. OP however has worked in tech for 20 years, yet made a very naive mistake - circular dependency, so to speak. They used a VOIP number from the same account as the recovery phone number.
To unlock your account, please enter the code in the email we sent you.
you might be able to evade google fingerprinting if you do all these things.
it would not surprise me if google pays to be allowed to crawl everything that touches google for even one tick, so they may still connect the dots when the AI sees a browser activity graph just like your last one. Who knows how well a VPN my hide your breadcrumbs, i just avoid making accounts with google or letting any overt analytics through my browser.