(I ran into a similar issue with the Oculus/Meta Quest 2 and Facebook login tokens. I reported it as a vulnerability in the Facebook account system and it was fixed eventually.)
(I ran into a similar issue with the Oculus/Meta Quest 2 and Facebook login tokens. I reported it as a vulnerability in the Facebook account system and it was fixed eventually.)
There's no reason why tier-1 support has to be this irredeemably useless. Just put someone in the loop who knows when _not_ to blindly follow a script. It really isn't that hard.
There is. They're probably non-Google employees, leased en-masse from the cheapest support center Google could find.
It is a deliberate choice to offer inferior support that isn’t able to deal with security issues.
> While our highest-impact services (e.g., Google Wallet, Gmail) are designed to make cookies expire very shortly after the user logs out, we believe that most potential exploitation vectors for this behavior fall outside the security model of modern browsers and operating systems, and can't be meaningfully mitigated by any single website.
> Check this link for more info: https://sites.google.com/site/bughunteruniversity/nonvuln/co...
Note: The issue I submitted was related to revoking all sessions (authentication) as well.
I don't think OP wants to claim a bounty (and anyway, probably doesn't have the details needed), OP just wants the issue fixed. Getting the issue looked at by someome who cares is more likely in the bounty program than through google customer support, because bug bounty triagers need to be empowered to communicate with people empowered to fix issues and google customer support isn't so empowered.
In a good customer service organization, an issue like this should get escalated, but that's not the reality at google, and not at too many other places either.