For anyone else reading, I'll just say that we all know there are tradeoffs between security and usability and we can actually have a good-faith discussion about that if we want to.
For anyone else reading, I'll just say that we all know there are tradeoffs between security and usability and we can actually have a good-faith discussion about that if we want to.
Thus, as long as the total number of hijacking+lockout decreases, it is a useful policy from the utilitarian perspective. Of course, hijacked people don't cry for help as much, and neither they blame Google as much.
People think a better customer service would somehow solve the lockout problem, but they need to understand that customer service has the same hijacking vs lockout problem, and they can only help if they have better identity verification methods available to them - e.g. if Google asked for government ID for opening a Google account, this would work - but if Google did that, people would scream. Without properly established identity verification methods, the customer service can't improve the precision and the recall. Thus, the current choice for the users is to use a better identity verification method - like security keys and using Advanced Protection, as non-phishable auth does not need complex and elaborate heuristic based protection, and set up a chain of recovery accounts, with all accounts using the security keys and/or Advanced Protection.
I have never bought into this regressive corporate security model in which my desktop computer is supposedly less trusted than assorted web app accounts. Unless I've opted in to something different, knowing the password should grant basically full access to the account. If there are additional rules around changing the password or other sensitive meta tasks, then those need to be spelled out in a well defined manner, and not punted to some opaque fickle machine learning scheme based on IP addresses, browser vulnerabilities, phase of the moon, etc.
The lockouts are there because of how easy it is, without them, to compromise someone's email access. People leave their email password lying "in the open" all the time (for a very broad definition of "in the open" that includes things like "re-use it in another site that gets compromised, and use the same username on that site so a cross-site attack attempt is basically a free action for an attacker to take"). When a Gmail account is compromised, people lose everything digital because they've routed their entire digital security story through their Gmail and it's a trivial operation to harvest all that data once an attacker has access. So the damage to an individual is massive when a Gmail account is breached. And since Gmail doesn't actually know who a person is, correction of a breached account is extremely painful (consider, for every method Google might add to prove your identity to restore ownership of your account, how a malicious actor could use that approach to steal your account).
I've been on the receiving end of a Gmail lockout (cooked a phone on vacation while my OTPs were stored in an envelope at home), and it sucks. But it sucks less than having my whole digital life story (access to HN, access to every forum I'm on, access to every hosting service I work with, access to every bank account I own) compromised because that Gmail account is the receiving target for every "reset your password" flow of every service I operate with online, and I'm the average use case.