There are no good answers here. A lot of things that work as one-offs or rarities will stop working if everyone does them. If there's a FCC form you can file that short-circuits Google's current process, and it becomes popular, that form is going to stop working. Restoring your access to a locked account is simply less important than ensuring strangers can't "restore" access to your account.
Obviously, one good change Google could make here would be to refuse to accept Google Voice numbers as an authentication factor.
There have been complaints after complaints about people being locked out of accounts, and there are no easy ways to recover - often no way at all.
To say that the paid support you're paying for can't help you access the service you're paying for, that's a bit rich.
> Restoring your access to a locked account is simply less important than ensuring strangers can't "restore" access to your account.
That's a false dichotomy. If you can pay, say, $200, and get 30 minutes with a tech who has access to your email and can go through a manual, interactive process to verify you are who you say you are - for example, if you can prove you hold the credit card that's been used to pay for Google One for the past couple of years - well, these "strangers" are going to have to work REALLY hard to "restore" their access to your account. Probably well more than $200 and more than it costs to install a keylogger and sniff your password anyway.
Think through what you'd hope Google would be able to do here. How do they authorize the request to unlock the account? Now imagine a well-funded adversary that knows exactly how Google's processes work (probably because they continuously pay for accounts and have them reset, to track what Google's doing). What's the reliable signal Google can use here, one the majority of their users actually have access to, that they can quickly execute on?
There are companies that have relatively quick Account Recovery processes through customer support. But those companies either aren't worth defrauding, or are regularly but quietly defrauded.
Remember, this is the most valuable account most people possess.
Nothing? Google sends postcards to verify business addresses already. If it's good enough for the bank to send me a card and PIN via post it should be good enough for Google. We have laws in place to deal with estranged spouses breaking into accounts.
A well funded adversary WILL take over your Google account. They'll do it by installing a keylogger and stealing your cookies, they'll do it because they know what signals the account recovery process is looking for - much better than you do, they'll do it because hacking you is far easier than hacking Google. (Two-factor authentication done properly, with printed backup codes in a safe location, can prevent hijacking most of the time.)
Second, Google accounts constantly do get hijacked every day. This draconian status quo might have been justified if it would prevent all hijackings, but it doesn't.
Third, my Google account is not my most important account. My bank account and portfolio which hold my life savings are arguably more important. But somehow I'm not worried at all about losing access to them.
Again, no system is perfect and it's mathematically impossible to identify the correct person for every account. But I still believe you can get the same false positive and false negative ratios without getting blog post after blog post from people who are completely stuck.
My point is different. Recovery is the hardest problem in authentication, but when you're as big and as significant as Google is, you owe it to your users, paying or not, to get it right, however hard it is.
There's a single potential client (maybe two if you add Facebook) who seems to be showing no interest in getting it right. Not the best business proposition.
But the account recovery problem facing Netflix or Github is different from the one facing smaller companies which is different from the one facing Google. I honestly doubt there is a one-size-fits-all solution, I definitely don't have it, but I'd be happy to be surprised.
In any case, lacking that, one could just walk into a Google office with a passport there. There are official ways to do authentication if these corporations really cared.
It's not rocket science. All banks can do it. It's just a tiny bit more expensive than saying "fuck you" to 0.1% of your customers.
To get someone able to actually make decisions, especially when they are against a measure the system automatically put in place following its programmed or AI-.derived rules, you need to go at least two levels higher. Even "managers" often - usually? - only have digression within pre-determined possibilities and scenarios.
It's going to be like this: https://twitter.com/cnbc/status/1447916881009127430
I'm not enough of an influencer to get my rants here noticed.
It all comes down to which direction, and how much, the money is flowing with them.
According to this article being a Google One member didn't help them.
edit: As people are pointing out below, however, is there no way to use Google One support if you are locked out of your account?