How likely is losing a Google account?
jefftk.com
jefftk.com
1. if something goes wrong, I can reach a human without needing to write a viral blog post first. Other services pay for a customer service department.
2. I trust FastMail more to not shut down their product because they got bored. Sure Gmail will probably not go away, but I'm honestly not as confident about Google Workspaces or whatever it's called now for individuals.
3. I'm tired of acting like using products from an ad company is a good idea. People happily use an email service, browser, OS, and more from the modern DoubleClick without a second thought.
More generally, how do you actually get a measure of risk between two providers, when the absolute frequencies of measurable events are very low?
It seems plausible to me that FastMail could have 10x or 100x the level of security incidents as GMail, and it would still net out to an undetectable difference in the number of public complaints.
If we had internal data… but of course we don’t.
The opposite of that is, you do not have a way of recourse, ever. Even states have some.
"I don't know if you wanna entrust the safety of our email to some silicon diode."
All joking aside:
I mean... we already know that taking the humans out of the loop leads to undesirable consequences (like losing your Google account with no recourse). So the only question is whether or not the consequences of one scenario or the other is particularly worse.
This i going to be funny if you get locked out of your bank-account or you have to lock-down your credit-card...computer says no.
Should we do the same for accusations of crime, get rid of judge and jury, consult a decision tree on whether you get the electric chair
(or maybe, they perfectly know it, but don't saying out too loud)
I suppose eliminating humans is a security win, but HN is full of stories of AI systems failing and banning accounts for essentially nothing. Not having a human to appeal to is far riskier to me. It's not like these AI systems can't be gamed to knock people offline. I'll take the risk of having humans involved -- it's far less stressful.
I'd be willing to bet that gmail has a couple of orders of magnitude more users than fastmail while also providing a substantially bigger inbox (than the cheapest fastmail option), and providing the whole thing for free. I dont think it's surprising that they make trade-offs to support that model. Just think of how many support staff you'd need to support 1.5 billion users!
> HN is full of stories of AI systems failing and banning accounts for essentially nothing. Not having a human to appeal to is far riskier to me. It's not like these AI systems can't be gamed to knock people offline. I'll take the risk of having humans involved -- it's far less stressful.
I don't think the trade off is that simple. There are plenty of stories of support staff getting scammed in to incorrectly providing access to accounts. Is one better than the other? It's not a clear choice imo.
Google has a shitload of money, they can afford hiring enough staff. Cost is a lame excuse here.
What is needed is legislation or some practiced standard regarding real-person online-id so that losing access to your email account doesn't nuke your ability to operate online in a way that requires you to verify your identity even pseudonymously.
That said, I have issues with spam being delivered to my organization's group aliases and I can't report the spam because it flags it against my group alias not the original sender (!) I can't turn spam filtering on the group alias because it flagged legitimate emails from our customers. So I'm kind of stuck between a rock and a hard place, with no one at Google to talk to about it.
The strongest statement you can make about the standard HN Google account outrage post is that the complainant is unaware of or unwilling to admit to the behavior that got their account suspended. Drawing the conclusion that all such complaints are false positives is not warranted by the evidence.
To me, this is analogous to backing up your BitLocker key with your online Microsoft account. Is it the optimal approach to security? No, but the far more likely risk factor is losing your key locally and then losing access to all of your data. I'll take the peace of mind that comes with knowing I can speak to a human if things go sideways. As an added benefit, I've been able to speak to a human when routine service issues have come up and it's been a pleasant experience.
I would contend that if you cannot reach a person, you cannot trust a system. And that has generally held in the entire history I've been on the Internet. I chose my web hosting by who had phone support, I've had the CEO of Fastmail respond to my support tickets before. I have yet to be betrayed or compromised by a single platform where humans were involved, but automated systems have failed me regularly.
This is true of offline systems as well. If you want a security system to protect your business, you may have keypads and sensors and things, but you also have a monitoring center staffed by people who can see events in real time.
I think our industry has had a fantasy that complex enough math problems can provide real security, but I would hope by now the cryptocurrency market would've put that silliness to bed by now.
Google's algorithms make entirely too many errors.
"I can't get my account back unless a viral account of my problem makes the front page of HN" is an unacceptable risk.
Obviously any real person losing access to their account is a rubbish experience for that person, but an error rate of 0% is not possible with any system (including those with plenty of humans involved) when there are billions of users involved. I think a much more interesting question is "what's the acceptable error rate?"
Please. Google has an entire team devoted to account abuse quality research.
https://storage.googleapis.com/pub-tools-public-publication-...
I don't think it follows that you need to speak to an affected user to confirm they were improperly locked out of their account. You could have a human review the account history and the steps that led up to the suspension and so on to make a decision about whether it was a good decision or not. No doubt you'd get more info if you spoke to the affected user, but that in itself is not perfect (a scammers whole game is trying to convince google they're someone else, after all.)
I guess what Im getting at is that I think there is a lot of grey areas when you're trying to do account recovery at scale. No doubt there are cut and dry cases where people are locked out of accounts they've used for a long time (and that's shit for the people affected), but there are also plenty of scammers who'd put a lot of effort in to convincing a support person that they should have access to an account. I just don't think having support staff is the panacea it is often portrayed as.
Last year I had an email from immigration services and I had to reply within 10 days. If I lost access to my email, I would be deported right now. They don't call, they just email. Why? I don't know, but that's what it is.
On the contrary, if someone get's access to my email, what can they do? Send random porn to my contacts? No-one will care.
As long as I can call the provider and fix the problem, it is irrelevant.
Take over every account you have that's configured to send password resets to that address.
How do you balance that risk vs the risk of losing control of your identity altogether due to a technology control malfunction etc. though?
Firstly, I will say this incident was unacceptable, and we were deeply sorry about it. However, it is also the only time it has happened in our over 20 year history (to the best of our knowledge of course). We already had several projects underway to improve the security of account recovery at the time, which unfortunately hadn't quite landed yet. Since then we have introduced an automated recovery tool with a very carefully designed flow (more info: https://www.fastmail.com/blog/security-account-recovery/) that securely handles most common cases (e.g., forgotten password, or user's account stolen due to password reuse/phishing). Human support is still available, but any account recovery request can only be handled by senior support agents who have undergone rigorous training, and in the case of any doubt are escalated all the way up to our senior security engineers.
Elsewhere it's been mentioned that different people may have different priorities in balancing ensuring they don't lock themselves out, versus ensuring an attacker can never access their account. We provide some flexibility here. If a user has 2FA enabled, we must verify two separate means of verification to grant access, whether via our automated tool or support-assisted recovery. Users can also submit a support ticket to request we add a note to their account to never do human-assisted recovery.
I realise it's very hard to assess the security competence of an organisation from the outside, and for what it's worth, we think the Google security team also do an excellent job. But overall I think we do a very good job of keeping users secure while not locking them out of their own account.
Thank you, this is the most important observation.
Service providers should be providing flexible mechanisms to meet different needs, they should absolutely not be imposing a one-size-fits-all policy. That's the fundamental wrongness with google/facebook and their ilk.
Only I know what the security levels I need for any given account I own. I must be able to configure the policy.
Sometimes, I value my access above all else. With some other account I may value preventing access to others even at the risk of losing access myself. Other variants are possible. Only I know what the correct policy is in any given case.
Are you worried about an individual interested specifically in you, Jeff B, to get something worth many thousands of dollars that they know you have? Don't put a human in the loop, they're going to track you across Facebook/LinkedIn/local government resources, they're going to know more about your car registrations and when you bought your home than you know about yourself, and they're going to be able to very convincingly social engineer a human in the loop if one exists.
Or are you worried about a group of hackers continuously crawling the web for a database dump from some service you and ten thousand other people signed up for, or some flaw in the authentication sequence to automatically sign everyone in the database and all their contacts a spam network for pennies per person? Their scheme falls apart if they have to call a human, because it's just not worth the time to look up your public records and talk to a human about you.
Second, what happens after you get hacked? Are you more concerned whether you no longer have access to something very important to you? For example, if you've distributed business cards or have contacts stretching back decades with jeffb@gmail.com, losing that account might mean an old friend or business contact fails to find you again. Having a human in the loop for the last-resort password reset can prevent completely losing access.
Or are you more worried about someone getting access to the data behind your login? You've presumably got backups, so you'd rather no one ever had access again than some malicious third party got the password to your crypto wallet, SSH keys to your website, or other private data.
Those have very different ideal responses. Unfortunately, most people tie both categories together in their single Google account, or in an Amazon account tied to both shopping and AWS resources.
* For your own security (from theft) we'll hardware lock your phone. Best to throw it in the dumpster if you forget the password.
* Can't allow people to repair their own hardware. What if kids try to do it and end up burning the whole apartment block. Best to forbid it for security.
* You can't film public institution: it's a security issue.
* And now: can't allow humans to operate business decisions. What if they're socially engineered? Best leave everything to automation and fuck you if you slip through the cracks.
It's funny because in the airplane industry, even though planes basically fly themselves, companies still want pilots, because that's what people are best at: solving unique problems as opposed to repetitive issues.
I think this is a relevant article: https://arstechnica.com/gadgets/2022/01/google-relents-legac...
Anyways, basically agree that gmail isn’t going anywhere, just a gmail-related story of people depending on a new flavor of gmail/ google identity that was being migrated messily.
I used this for 10 years or so before realising they'd moved the backends as they were planning the workspace thing and they were separate - you couldn't share between the two, loads of features missing etc .
Typical Google - all the ideas, no execution.
Your link is also talking about the no 2FA case, while the article is recommending 2FA with (multiple!) hardware security tokens.
https://support.google.com/mail/answer/6603?hl=en-GB
> We will not scan or read your Gmail messages to show you ads.
the veins dried up back in 2017.
And I don’t believe that PHP is the best ;-)
Wherever you paid for the product seems to have little impact, the reality is that all tech giants carelessly invade your privacy with no recourse for the user.
If anything, companies try to double-dip and serve multiple masters. See: the security and privacy mess in smart TVs. Last I checked, LG wasn't giving their TVs away.
This is true, and you transition from customer to eyeballs once you take delivery of the product, but it is also tempered by the fact that they would like to sell you your next TV as well.
In fact there is a pretty strong argument that they are leaving money on the table by not doing so.
Imagine you like your gmail and you have had it for the past decade. If Google charges only $1 per year across say a billion users that is a billion dollars.
Even if they lose some users at the margin it may makes sense...
According to wikipedia gmail had 1.5 billion active users in 2019.
As internet services mature and stop growing exponentially it makes sense to charge for them.
Yes it is true that some might switch but what makes more sense from the perspective of most users?
I long for a post advertising world. What cataclysmic event or human evolutionary change could cause that, I wonder.
Is there any sci-fi that has a world without advertising or is that so far-fetched it’s unimaginable to even futurists?
Even funnier, if Google search worked effectively for product discovery the vast majority of advertising would not be necessary.
I'll just let LG collect my viewing habits if that's what it takes for a good experience. But I did decline all of the agreements that have anything to do with data collection, so hopefully they're not being overly intrusive anyway.
This way I still have a "dumb TV" (apparently impossible to get now).
Second option would have been to get a projector.
It seems fine: no ads, nothing spamming, and it has an option to not share any data, which presumably (!) it pays attention to.
No, but they're selling them at cost, and using monetization tactics to make up for that over the long term.
Fortunately, it's not so bad, just run firmware updates after you get the new tv, and then disconnect it from the internet.
Not necessarily, and in fact this case I would disagree.
I trust Google's security 10x more than that of FastMail.
The 'advertising company' reaps in billions of $ with which they can get all sorts of good engineers for 0-day research, exploits, updates.
They have a lot more of a reputation to defend.
Without hard evidence, I suggest that Google is probably 'more secure' than FastMail. Certainly more than 'Mom and Pop Mail'.
Except for the bit where they read my email and advertise to me on that basis, which is admittedly an ugly tradeoff.
If you are paying for google apps this is not a trade-off. I dislike how (as a paying) customer they continually push me towards google-only <everything> but they don't require it.
> Except for the bit where they read my email and advertise to me on that basis, which is admittedly an ugly tradeoff.
Iirc, Google reads your email, but explicitly says they do not use what they read to personalize your ads.
> To provide you features like smart inbox categories, Smart Compose, and spam detection, we use Gmail data to provide a more intelligent email experience and keep you safe. - https://support.google.com/mail/answer/10434152?hl=en
Famously, a while back, at some Google subdomain, you could see a list of all of your payments extracted from your emails, but I'm not sure that still exists.
I trust Google security to protect Google, not me. For example by blocking my account.
> They have a lot more of a reputation to defend.
Actually no, if Fastmail pulled the shit that Google does, they'd be out of business.
Any company will protect itself first. As they say in the VPN world, "nobody here is going to jail for your $5/month".
that didnt stop them from having vulnerabilities in gmail that allowed anyone to fake the dkim verification and pretend to be the CEO of google, which they then ignored until someone did in fact do this, to prove it :)
The overused phrase "more secure" doesn't mean anything without context.
To evaluate the security of anything you first need to identify all the threat models that concern you (and perhaps call out the ones you don't care about). Then evaluate each solution against every threat you identified.
For instance for the threat of the vendor itself sabotaging my access to my account, I'll score FastMail far better then gmail.
I just finished reading Postmail For Dummies. Since I'm charging $5/mo for email accounts, you'll obviously want to migrate your gmail over since my solution is so much more secure.
Just an interesting data point. It wasn't my intention to label the payment that way. It is what it is, but, just as OP seems to be believe, I would expected the issue to be resolved faster. Though, perhaps if I were to receive a "fraud" label on a non-paid account maybe I would be blocked to this day.
Having said that, I'm still not going back to Gmail.
Moved to Fastmail. No issues since.
Now I use proton as primary and gmail as spam.
gmail's quality right now is absolute garbage.
Strong passwords, hardware security keys, shared secrets meant for offline storage, SMS challenge, other accounts, snail mail address verification, notarization (governmental identity), voiceprints, time delays, etc. Each one represents its own tradeoff of convenience versus reliability versus forgeability versus privacy.
Users should be able to pick their own policies. For an email account where I've already provided my real world governmental identity, I'd most likely prefer snail mail address verification plus notarization (combined with notifications to the account and a waiting period). Whereas for another where I've deliberately avoided spilling my governmental identity, I should be able to express that a password plus hardware security key is the highest level of verification there will ever be.
Furthermore, companies need to make their own rules for falling between everyday access to account recovery explicit, and allow users to express preferences there too. There should be no cases of the wind blowing from the east so we require account recovery today, forcing users to be policed on what IP addresses they're coming from, etc.
I feel much better now that my Google account is only used for Android and YouTube.
You can do that with GMail too, upgrade to the workspace account. I had some issues with it last week, and I was able to reach a human and get it resolved soon.
This is regardless of Google. Reaching humans is impossible with "Outlook" free email accounts, but amazing with Microsoft 365.
To me, this introduces a new way to lose your account that isn't there with a free email service like Gmail.
[1] https://www.emaildiscussions.com/showthread.php?p=622760
[2] https://news.ycombinator.com/item?id=29988359
[3] https://www.reddit.com/r/personalfinance/comments/d1okxu/cha...
When I missed the payment they sent me this:
"You can still use your account for now. If the subscription is not renewed soon, sending and receiving email will be disabled. If the subscription is still not renewed after a few weeks, access will be disabled. Eventually, the entire account will be deleted, including all stored messages."
Not sure if this counts as "policy reason" for the article's purposes; he sort of dismisses payment disputes. I could argue either side about whether a suspension like this is reasonable. In the Google Pixel case the chargebacks mostly start because Google outsources hardware support to a bunch of unreliable third parties. Some of whom seem to eitiher lose or just be stealing customers' phones when they are sent in for repair.
My takeaway was that if I was ever in a dispute over a couple of hundred bucks for Google, I would not risk a chargeback for fear of retaliation. My account is one of Google's very first, when I worked there I launched one of the first products to ever use a Google account. I have no faith that as an outsider now I'd ever get a reasonable hearing over an account dispute.
My takeaway from that is to never spend more than a few quid (i.e. money I'd care about losing) on anything linked that directly to Google.
Google no. I am very very close to being able to kill my google account though I probably will just leave it parked.
Believe it or not Google Voice is the one thing holding me at the moment. Nobody offers the same quality service period, let alone free. Come at me HN, I'm open to alternatives. Google Voice also has one killer feature nobody else has; the ability to make and receive calls using your carrier voice service and not DATA. Generally a higher quality connection that on most plans these days is unlimited, where as a lot of plans still count data usage whether it's a "unlimited" (but throttled) account or not.
OpenPhone is the closest I've found and seems their customer service is horrible, I see people on reddit complaining about them all the time.
I still have a shared calendar on Google but only because I can't convince my wife to try something different. I used to be all-in on Google but have spent the past 2 years getting away as much as I can.
I hear OSM has some decent map and navigation solutions now, but for me Apple maps long ago passed the touring test. I only trust that Apple with all their positions and statements on privacy will suffer irreparable harm if it is discovered they sell user behavioral data like google blatantly does.
It's the lack of a central, accountable point of contact for everything under the "Google Account" that's the real problem. Since its very beginning Google has been bad at consumer relationships.
My point is that to avoid even having to consider this choice to make by never doing anything that I might ever want to charge back. Separation of concerns: don't do (significant) money stuff with Google, then money stuff can't affect your other uses of Google.
----
[0] Some have a lot of contacts who know them at their @gmail address, getting people to update your contact info when you deliberately change address can be enough of a faf, imagine having to do it without warning. Some also have other accounts where they login via Google, they need to make sure those are transferred to something else (if possible).
[1] I have nothing irreplaceable in Google's sphere (my phone contacts & other content is backed up there, but not only there) though there are a few shared photo albums and so forth that I interact with using that account.
[2] Even if you intend to move away from Google or other large multi-pie-fingered company, and are actively doing so, you want to do that at your conveniences not with them chucking you out in an automated hissy-fit.
And my takeaway is that it is high time that these corporations that hold people's livelihoods in their hands got regulated like public utilities...
I wanted to buy 2 pixels from them. Put the order in, no news for 7 days, at the exact 7 day mark my order gets cancelled. Tried talking to customer support with no success because there isn’t any.
So I put the order in the second time and the exact same thing happens: after exactly 7 days, my order gets cancelled. I say f’ it and buy from a local dealer, with next day delivery.
A few days after the fact, I try using my credit card for something and my transaction gets denied (I had a -200 euros limit). I call the bank and they tell me that there’s a hold on my account from Google, for the price of both orders (about 1500 euros I think) and they are waiting for the funds so it can clear. My only two options is to talk to Google to cancel the charge (lol) or wait 30 days.
I simply closed my card and got a new one.
A few months later I started getting notifications that transactions on this card are being rejected - someone was trying to buy stuff for 1-3$ with my card but it was closed so they didn’t go through. Since I mostly use virtual cards for online stuff (which Google doesn’t like), and the physical card rarely, there is a really big chance that my credit card number got leaked from Google, but there is no way for me to prove that.
As far as I know, we've never lost control of credit card numbers and had them leaked. We actually work very hard to make sure humans can never see card numbers (our internal controls are more strict than most banks and card networks).
Also, I didn't think we would hold an auth on a card for 30 days (normally it's less than that). For the MCCs we charge payments on, I believe Visa and the others will only hold an auth for 7 days[0]. If the Auth is staying on your card for longer than that, it's likely your bank is holding the funds, not Google. We try to always cancel auth holds before they expire, to make sure we don't have lingering auths like you saw (I've tweaked this previously due to complaints like yours).
I can maybe look into the payments on your account if you'd like (my work email is in my profile), but I wouldn't be able to reply. It would just give us data if we are failing to cancel auths in some cases.
[0] https://www.chargebackgurus.com/blog/credit-card-authorizati...
Also thank you for the offer to check my account, but there’s no need for that as I will try to never ever buy anything directly from Google
Google knows more about me than the CIA and FBI. If they truly want to blacklist me, I'm not working around that without the aid of operators I'd rather not be associated with.
I think this is a bit dismissive of Fastmail: in all three of the linked reports (2017, 2020, and 2022) Fastmail has apologized and reinstated the account or provided some other mitigation.
Nobody is perfect, any service will have bugs causing lockouts and false-positive fraud claims. But what makes Google untrustworthy is that they don't seem to have any recourse if you are caught in a mess. To the point where engineers in other Google departments can't get human support, and the linked case which made mainstream news did not get his account back despite being proven beyond-doubt innocent.
A good service can make some mistakes, what differentiates them from a bad service that they attempt to correct them. Like how a good company can do layoffs if they provide good severance and also cut top executives' pay.
[1] https://techcrunch.com/2017/12/22/that-time-i-got-locked-out...
The HUGE difference is both Fastmail and I assume Protonmail (I only have personal experience with FM) actually have customer service departments, with real people.
And haven't there been cases where developers who'd had accounts banned in the past got hired somewhere and ended up with an employer dev account linked to the banned personal account and also locked? And of course there's the whole question of phones - banned from Google and the entire Android ecosystem? Not like Google can't figure it out if you create a new account with the same phone number and geolocation.
Rather, accounts were banned because he asked people to vote via comments using just single emojis, and the repetitive emoji comments were classified as spamming, so accounts were blocked for spamming. Once Google recognized the error of over-aggressive spam classification, it reinstated all the accounts. [1]
[1] https://www.engadget.com/2019-11-10-youtube-reinstates-banne...
Obviously proving a negative is a problem, but would anyone be surprised if small bans like that had actually happened and never got fixed? I'd be surprised if they hadn't happened.
But I also very much want there to be forgiveness somewhere in these systems. The historical, classic, "It was just a joke" doesn't cut it, but I also am not heartless, don't think the punishment here ought to be forever. I want there to be reconciliation, reform, appeals available. I personally am a huge fan of better digital justice efforts. But these efforts need to start & take off as ground roots, voluntary systems, to avoid premature & hardening regulation. I think we need some banner sites to bother trying to do better, which so far no one at all has. Trying to force change at the top seems foolish when we have tried so little, when we still know nothing.
I'd love to see some newspapers build "Digital Juries"[1] for abuse/moderation, or see some transparency floated. Just having more open processes would also be very helpful, versus how close to the chest these things are played today.
Oh, and it's profit-driven so there's strong incentive to reduce costs, needs to do expensive content and comment moderation, has what could be classified as a toxic internal structure and a bunch of techies, which leads to automated moderation (e.g. https://arstechnica.com/gadgets/2022/12/youtube-moderation-b...). Because automated moderation can be scaled cheaply, doesn't need to be paid wages and benefits, doesn't complain about mental health, and if something goes wrong, you just point and say "it was a computer problem" and that blunts most of the complaints because who's even responsible at that point?
And while it has all this control it has limited options for punitive actions - Google can't really levy fines, its punishment options are effectively full or limited bans from some services (e.g. no commenting ability), temporary complete bans and permanent bans. If those bans can be circumvented easily they're kind of toothless, so with the information it has it can easily detect most bypass attempts.
So financial incentives to automate and reduce appeal options, plus limited enforcement options weighted to the heavy end, plus widespread use as an identity provider. There are probably a lot of people out there for whom a week in jail would be less of a long-term life disruption than loss of their Google account.
Neither Google Search, nor Android, nor Youtube require a Google account.
If you want to follow someone on Youtube, Microsoft Edge will let you do so, without an account. Because it's just a web property & not an app, this sort of thing is trivially easy to do.
> There are probably a lot of people out there for whom a week in jail would be less of a long-term life disruption than loss of their Google account.
This is really a great point, and I totally agree. It makes me wish for two things: as you say, a lot more use of temporary bans. AFAIK Google does not do this anywhere. This is a powerful warning & wake up, with less long term impact. Second, a "strikes" policy that has some forgiveness built in. Someone who is one offense away from a forever-ban is in a miserable spot for their whole life, and they should have some ability to get back into graces. That should be part of the system too.
Of his own chat.
The chat has slow mode. Not like they can ddos the service.
That's not an attack.
Google should be ashamed of themselves for having an automated system that banned thousands without any kind of human loop review.
Right now we don't really have any way to know: was this corrected? Maybe Google doesn't do this anymore! But we have no idea. It would be a more moral & just stance for Google to actually talk about this kind of stuff, but, like most companies, there is little communication or updates on how these things work. The triplines are all invisible, the effect happens at digital speed. I find that to be one of the worst things about where we are; it is a intense info-industrial mechanization.
I still don't see how except automation we expect to build affordable at-scale systems. But the AI deciding your are an enemy & flipping the bit suddenly, like it does, is reckless, cruel, & shoddy.
When I still used Gmail I was always worried something like this would get me locked out of everything. I use YouTube much more now that my e-mail is safely stored elsewhere.
You mean, Google's support services entirely failed, but a huge amount of social media attention eventually got them to fix things.
It notes human moderators denied appeals in the article you linked.
https://twitter.com/markiplier/status/1193218509804695552
markiplier complaining that not all accounts were reinstated one day before that article, I doubt everything was sorted out by the next day.
having personally fell through a crack with one major service (not google) I feel like some poor souls are still looking at this bitterly.
"Luckily" I had enough identity documents to prove to Google's satisfaction that I was who I said I was. But even after I recovered the account, it was all screwed up.
Since then I've dropped my reliance on Google. I don't use them for sign-in, my mail gets regularly backed up, I use alternative apps where I can.
Google scale only works when people and processes are infallible.
Google boasts that it doesn't do customer service because it can't scale to meet the demands of their user base.
That can only work if their systems and processes never cause a user to have to go further than an FAQ page or community support.
Given that Google are fallible, you end up in a situation where users' have a poor experience and cannot contact someone to resolve it.
I'm in a weird spot. I find myself surprised at how actively I defend these company's right to speech. Section 230 still seems like the bedrock that made it possible to have everyday people put words online to me, and I can't imagine renegotiating a way to preserve that while heaping liability onto those who offer online services.
Yet these completely mechanized processes, with no appeal, no humans, no way to get back into graces if something ever does goes awry, is curdling. I cant imagine mandating change, I can't imagine what we could demand that would be reasonable, but I also think this represents one of the worst possible sides of technology & the world; is most quintessentially de-humanizing.
In theory, extremely mechanized companies could have to either fix their customer support operations or face an endless stream of lawsuits. You can let the market (again) decide whether they want to spend more money on customer service labor or lawyer labor.
Which is a huge red flag, and a fantastic reason to avoid relying on any Google service.
1. Merely looking at published noise may vastly underestimate the size of the problem. Lots of "normal" people including one close to me have several accounts containing parts of their life history lost for one reason or another, and just accepted it and moved on.
2. "Kids in the bath", ha. Carefully framed photo to avoid sensitive areas, taken with a tablet that happened to be handy that is not usually used for photography. Next thing I know I see them on another device. Darn thing had Google Photos with cloud sync enabled by default! Not for long, and I made sure to purge those photos from the cloud. But it can happen that easily.
Exactly so. My rule of thumb is that for every problem/complaint you hear about, there are [at least] 100x that many whose unhappy campers won't/can't bother to do anything about it.
But damn are non-Google ecosystems bad. At work we use m365 and everything is atrocious compared to Google. Loggin in is a mess, email search is dreadful, OneNote search unhelpfully defaults to searching the current pagwe, integration with Android is weak, Outlook Calendar never seems to do what I want it to and doesn't seem to handle location in any sane way... I could go on but every time I switch to my private machine and Google-first setup, it's like a weight has been lifted.
And really, the only faster email setup I have ever used was mutt right on the MTA. I haven't used Fastmail but ProtonMail (my backup choice due to their combo mail+VPN+drive offer) certainly doesn't feel faster than Google.
That's interesting, can you expand on this?
Whereas I find Gmail both often misclassifies legitimate mail as spam, and fails to catch obvious spam, the biggest issue is it rarely is fixable by my actions, because it's mostly based on Gmail-as-a-whole's perspective on spam. My Gmail is also receives an absolute deluge of junk even though I haven't used it as my primary mail since 2016. I have a somewhat short Gmail address and I strongly suspect it gets dictionary-spammed because the server name is a given, it also gets signed up to random things I never signed up for (including the NRA and Shutterstock, both of whom I had to contact and ask to remove me).
If this trivial complaint is the worst you can think of for OneNote then that shows what a good job they've done. I actually hate how good OneNote is because it doesn't work on Linux (as a native application) and there's no good alternative that does. The usual answer I hear is to use a wiki but one of OneNote's killer features is how good its offline capability is when using a notebook on a shared drive, and an online-only wiki is about as far from that as you can get.
(Ctrl+f to search current page, ctrl+e to search everywhere, by the way.)
The focus is almost never where I expect it, the notes overlap each other by defualt, the sync takes enough time to notice every time you make notes on your laptop before a meeting and then try to use them off the phone.
Actually, don't compare to ecosystems at all. Specialized service providers are much much better.
My google inboxes are full of spam. To catch the companies that were causing all of this spam, I setup a catchall email account on a non-google email service and switched every vendor over to a dedicated email address (i.e. hn@foobar.com, homedepot@foobar.com).
I expected to catch a tonne of vendors "red handed" sharing my email address, since spam was so prolific on gmail. Nope, I simply don't see spam anymore. In the last four years I've caught exactly one vendor sharing my email address (TicketMaster gave my email address to Warner Brothers).
Given I haven't changed anything materially with how I share my email address (it's still in my git commits as code@foobar.com, still on my website as website@foobar.com, etc., if anything I share it more freely now since I know I have control over each inbox), I'm lead to strongly believe GMail has a unique spam problem.
Dealing with GMail's spam problem isn't worth my time. That is amplified by the risk of me getting locked out of an email account. I have one Google account with files and emails dating back to grade school I can no longer access and no approach to "recover my account" has worked in the last 5 years - I've even paid Google for support to have someone tell me there was nothing they could do.
Google is a massive liability for me. They are a huge risk trusting them with anything that doesn't have a dedicated customer support team, a large part of their business model is to waste my time instead of charging me $$ for services rendered, and they do a pretty poor job of maintaining a level of quality in their products like GMail.
Whenever I have to deal with Google I get the distinct feeling that they consider their time infinitely more valuable than mine. I don't like doing business with people who are willing to waste my time like that.
The two sources I have: - Leaks - Guesses - eg. webmaster@domain.com - Kickstarter
Kickstarter gives over your email to projects, and now I get get lots of kickstarter type spam where it's clear projects have shared it out. It's annoying. My fault for using a real email with kickstarter years ago.
I'm pretty sure all the spam I get on my original account (20 year old email, first@firstlast.com) are also more leak related than anything else. That email has been around for so long, and is in a lot of leaked cred dumps. Whenever there's a new dump I get a small spam uptick.
I've been segregating passwords for several years, but nothing like the age of my original one true email.
I recently bought a whole new anonymous domain too, to keep non-personal email off my personal domain (it's firstnamelastname.com). It's fun to have a second domain and totally unique emails per vendor, but doesn't seem to do much. I suspect this is also a volume/value thing for spammers. Everyone has a gmail so search/guess/spam those and it's easy. Individually targeted attacks on domains with very small address lists aren't worth it, and almost worth removing from your spam attack because someone with a small custom domain isn't likely to fall for it. Similar to the delivery typos approach of selecting for people who aren't sensitive/cautious to correct language.
I find Fastmail does a really good job at detecting spam in general too.
I'm convinced that companies filter out custom domain email addresses when they share and spam user data.
I had Google hosting my family's email for a long time (I had one of those grandfathered free custom domain setups).
It wasn't bad and it was free (!), but:
- Google threatened to cut me off. - Wife's account needed attention to keep it under the disk space quotas. - Google had creepy marketing based on private email content (making you worry about what else they are doing with my private email content). - It was free. (Yes, I list that as both a positive and a negative, since it means they have no real responsibility to me.)
I migrated to fastmail and it's every bit as good as gmail with none of the downsides, for a small $/month.
Sure, Google backed down from terminating my service, but that reminded me not to rely on "free" services -- free is always limited. So I thought, "Fair enough, time to pay." I considered Google, but they did not make the cut.
As far as I know, email content was never used for ad targeting on any iteration of Workspace/Gsuite/Google Apps for Your Domain/etc. (And it hasn't been used for consumer gmail for many years either.)
Not that the details of how they use a specific information stream are all that important (if they aren't using one it's just because they've got something else better). The fundamental problem is that their interests are fairly heavily misaligned with mine. They want to make money by effectively mining my information and I don't like that and find it creepy.
Why trust those statements? Because lying would be a very bad idea. The lies would be revealed very quickly (e.g. via whistleblowers). The outcome would be expensive civil lawsuits, probably billions in fines, and a loss of trust in their $20 billion / year cloud business.
In my experience the admin side is the opposite. I only have a legacy Google Apps account to judge, so maybe the paid stuff is better, but MS365 has some pretty good tools when it comes to email.
However, both of them have absolutely brain dead policies sometimes. Ex: Google bounces mail sent to accounts locked for suspicious login attempts and MS forces you to give admin privileges to normal users that have to deal with messages that are incorrectly flagged as high confidence phishing.
MS is a double edged sword though. You get access to a lot of tooling on the admin side, but they very obviously don't care about small business users. The Business Basic accounts are more like paid beta testers than anything. You can see it if you look at the release lifecycle for a lot of the products. Ex: Business Basic accounts get app updates before Enterprise accounts.
I currently use MS for everything, but the bloat is starting to get to me. They can't stop adding features and everything there is starting to feel unpolished. They can't even keep their own docs / support up to date and sometimes support will send you links to stale information.
The support is 100% useless from both Google and MS, so I almost never use them and prefer MS because I get more tools to solve my own problems. The "confidently wrong" part of ChatGPT feels like a Microsoft product. Lol. They could literally replace their support with that "AI" and I bet people wouldn't notice the difference. That's not because ChatGPT is good. It's because MS support is so bad.
"My name is ChatGPT. I understand your problem and I'm going to help you fix it." >>> Proceeds to demonstrate a complete lack of understanding and doesn't fix the problem.
However recently the family moved to a new country. This basically isn't something google lets you do with a family group, and until you change your play store country, your play store won't have the local variants of a lot of apps, so you can't install them. You have to delete your family group, change country then recreate it. But you can't delete a family group with a child account. The only thing you can do is delete the child account. The help docs mention being able to restore it, but that didn't work, it just said it couldn't be restored. And since google doesn't allow an email address to ever be recycled once it's deleted, I forever locked my kid out of possibly having his firstname.lastname gmail address. Very frustrating.
Ultimately I gave up and used another way of contacting that old friend. The experience also made me feel even better than I already did about having migrated to a domain I owned and a non-Google provider for my primary personal email.
I also don't use any 'identity services' because I have no basis of trust in any of them.
For me, it all happened because I tried to purchase, of all things, Minecraft from the Google Play store and typed my CVV in wrong a couple of times. That locked me out of my email and all Google services for about three days while they did some sort of fraud verification.
While, yes, things can happen to FastMail, etc, the likelihood of having my domain stolen from my registrar (which is very possible) is a lot lower than something happening to my Google account. And, god forbid it did happen, in my experience, getting in contact with a human at a domain registrar is easier than getting in contact with a human at Google.
Curiously, his old Youtube channel stayed up for most of the year, he just couldn't access it, but it was removed too late last year. He created a new account and rebuilt his following, here's the original video when he lost his account: https://www.youtube.com/watch?v=Jn1b3DztWnc
The biggest issue to me is that Google has a history of not caring about customer service, or any sort of human touch to handle fuzzy situations the algorithms get wrong.
It's bad enough when it's all of your Google or Microsoft or Apple services, but it's going to get worse. I'm convinced the whole passwordless movement isn't much more than a strategy for big tech to completely usurp control of identity. People on Hacker News might not get trapped because they understand enough to have some contingencies, but the average person is going to end up with their identity completely depending on having access to an account at one of the big tech companies.
Just wait until they lobby the government and get "Passwordless Login" pushed as a preferred way to access government services. Then they own us.
And governments globally are already doing their own SSO services (the UK has had a version of this for 20 years) and some (Canada) are enabling partnerships with what they feel to be more secure sources of identity eg. online banking.
I think the fundamental problem with Google is that their policies are inscrutable. I wouldn’t rely on any one identity provider for everything I either, and would expect all services have a recourse for resetting your login settings when a particular provider no longer works for you.
What made me transition away from Google/Gmail as my identity provider was pondering the question:
How screwed am I if I get locked out of my Google account?
The answer: Well, if you're on Hacker News, you may have a chance of reaching a human. But if you broke a policy, good luck.
I'm paying $5/mo. for that to not be that screwed.
(I have family who got locked out. It does happen.)
The last message of my first account, areallygoodname, is spam. I couldn't be bothered getting the admins to recover it back. I just took the lesson that hackernews is really insecure due to allowing manual recovery.
But the article precisely addresses that:
For example, in HN discussions people will often recommend Fastmail or Protonmail, but they've had their problems too (FM: 2017, 2020, 2022, PM: 2018, 2019, 2021). Especially given that these are much smaller services I'm not convinced that the risk is lower there. Any system is going to have to handle this sort of problem, and you're not going to find one that never has false positives.
What I'd like to know is : do FM/PM more easily enable to talk to a human ?
Lots of large companies have a bunch of customer support agents who are easy to get in touch with, but entirely powerless to solve these sorts of problems: "Computer says no". They are just, to be blunt, executing flowcharts, and have no scope to escalate beyond that.
The only reliable ways to get decent customer support are, in my experience:
- The CEO is a friend of yours
- Your account is so large that a significant chunk of the company depends on you for their income
- You have an ironclad support contract
- Regulatory requirements enforce a level of customer service
Unfortunately, none of those are likely to apply to an average person looking for an email provider, and running one is usually impractical due to these large companies blocking small hosts. Next best thing is taking regular backups and having your own domain with a low TTL MX record.
"Um, I don't have an alternate email and my phone number changed when I moved countries last year."
They'll probably (and correctly) maybe make sympathetic noises but basically say too bad. Presumably this wouldn't happen with a (non-trivial) company where there's some level of known identity. But for an individual there would presumably need to be a last-resort process that required real-world identity verification in some form.
This is one of the reasons I don't like or trust SaaS as an end-user, at least for critical failure points.
It's not just about policy lockouts; the company can go out of business or get sold and the product shut down. Data leaks and breaches can be a greater risk since you're too small to target as an individual but all users collectively is another story. Outages, both locally and service-level, can prevent you from having access to your data when you absolutely need it (doctor or legal appointment etc.). Oh and they will track you, make you a perpetual guinea pig for A/B testing purposes and can change critical features that you depend on at any time of their choosing without notice.
There are trade-offs in the other direction, like the mobility and the convenience to access data across multiple devices. For historically expensive products (like Photoshop and Pro Tools), subscription based models make services more accessible. It's just too bad that we can't seem to land on the best of both worlds as the common case. I'd like a subscription model and the ability to sync data across devices automatically (preferably using e2e encryption) without the software being at all "web based."
What's the purpose of a recovery account, if you can't recover with it?
Fair disclosure: I'm not sure why I lost access to the account, but I had been planning on changing the password. There's a non-zero chance this was self inflicted. But it should have been recoverable.
There is a strong consensus forming in the tech community that core services like email or authentication should be delegated to google only as a last resort.
- What can easily be backed up and restored (eg. email, calendars), and so loss of access is easy to tolerate
Email, Calendars, etc can generally be dumped pretty easily using LDAP, CalDAV, whatever in a cronjob and saved locally. Drive data can obviously be synced off too. The value here is pretty low and it's pretty easy to do.
- The value of the email address itself (ie. if you need to go change a hundred accounts using it for signing in vs just change the MX record and send to a different provider)
This is the argument for a custom domain that you own with a different register, and have different DNS hosting, so you can keep it segregated and send email anywhere. You could move to Apple, Fastmail, etc with a custom domain pretty quickly.
Some sites will also send you an email to both old and new email and require hitting links you might not have access to if you lost email, or use email for 2FA. eg. Steam using SteamGuard which is all email based. Losing a large Steam library after losing a Gmail account would be horrible.
- The value of other account using federated GSuite sign-in. It's horrible to lose Google, but then also lose all the sites using it.
A strong argument not to use federated accounts and always use email/password (2FA obvs). 1Pass FTW.
None the above advocates for a specific provider, but personally I'm a fan of Fastmail. Not only because it's ad-free and paid for, but also because they advocate for stronger privacy practices, eg. random emails for accounts in partnership with 1Pass. I know you can use + addressing in Gmail but some providers and spammers detect and handle it. Truly random forwarding Ala Apple and Fastmail is better. Although, also, harder to move away from as you can't redirect those. I use Fastmail's domain and user forwarding. eg. service@service.mydomain.com forwards to my personal email.
It was a nightmare and a good reminder that an attacker with sufficient resources can create more issues than you can possibly dig yourself out of.
Even if you are storing passwords in Google account you should be able to reset all of them since you have access to the email.
"I put a little effort into avoiding grey areas (not filing chargebacks to Google, not taking pictures of my kids in the bath) but otherwise don't worry about this."
I was locked out of my Google account after using it in Italy and coming back to Germany. Unable to login: It would first ask username, password, then send me an a-mail, then ask for the code from the e-mail (which I provided) and then either tell me to enter a phone number (Google is not going to get it from me!) or alternatively:
“You're trying to sign in on a device Google doesn't recognize, and we don't have enough information to verify that it's you. For your protection, you can't sign in here right now.”
If that isn't dystopian.
I interpreted the phone number requirement as a signal that “had I setup 2FA, it would not have asked for the phone number but maybe just the second factor?”. Then I went on an odyssey to setup a Google account without linking it to a phone and with 2FA enabled (also not linked to a phone!). Seems OK so far, but the procedure is highly complicated and partially luck-dependent. I am probably going to publish it, because there are tons of articles about how to setup Google account without phone number, but none of them worked for me at the time :)
I still do not rely on Google for anything but the search engine which still works without any login...
I'd be interested, even if it was just a rough guide. My experience has been that some services apparently let you sign up without a phone number, but then try to extort it out of you either at first login (or worse) after you've used the service for awhile.
I've noticed some of my own old accounts (not google anyway) seem to be grandfathered in and do not have a hard requirement here.
Here we go: https://masysma.net/37/google_how_to_create_an_account_witho...
You might notice the date on that page being 2021/04/06 -- I had this in draft state for a long time, but newly put it online now. What has worked back then may not work anymore, though.
> My experience has been that some services apparently let you sign up without a phone number, but then try to extort it out of you either at first login (or worse) after you've used the service for awhile.
Yes, that is basically what Google did to me, too. It was not a new account either -- from 2012 (I still have the initial "registration" e-mail).
I just checked: I can still login into that account that I had created around 2021 when I discovered the "trick" as described on the website. It asked for username/password/2FA and that was it. I did not use it much in the meantime, though.
First dose is free, eventually you'll have to give the phone number for your safety.
Anything digital and online can be arbitrarily taken from you with no recourse.
Good breakdown for this person's use case.
I disagree with the conclusion above though. My experience (as a person who handles technical support around these issues, for customers of Gmail and more specifically ATT/Yahoo/SBCGlobal) is that many people that get locked out of their accounts do not understand all the options available to them to regain access. Also it appears, to me, that at least for Fastmail, their security protocols are a bit more friendly, less strict about how the security is applied (I.E not spamming customers to use the security methods, changing the methods willy/nilly without warning). Also Fastmail sends an email to your mail email account if you accidentally trying to use your main account password in an app specific use-case, I.E makes it easier to understand how the security measures are being applied.
Also the security measures implemented by providers that you pay for, appear to me, to be designed to be customer centric, rather than trying to create a blanket one size fits all approach to security that I feel google tries to implement (because they have so many customers). My meaning about this is that the control of the security options appear, to me, to be more in the hands of the customer to implement how they see fit, where as google security measures appear to be implemented from a cover our assess approach and not really designed for the customer per say.
I used to just log on.
I guess at one point, I gave them my mobile phone number. I no longer have that phone or phone number.
So now, google keeps sending a security code to that phone number, which I no longer own. There's no way to put in a new mobile, but I don't want to do that anymore, anyways. Nobody gets my personal info if I so choose, and for google, I so choose - they are not getting shit from me if I can help it. They also ask for a backup code, which I am positive I never had one of those for my google account. They never asked for security questions, I always have those copied if they do.
So I'm locked out of my google account.
My new email provider only requires a password. That's what I want.
Plus, as far as email goes, Google or Yahoo or any of those commercial providers can scan through all your email. People would not put up with this if someone scanned their personal mail that came into their physical mailbox, but for some reason, it is ok if google, the largest information gathering company on the face of the earth, gathers all their data and sells it to the highest bidder. Nobody would allow this on physical mail.
So now all my email goes to tutanota, who don't do this. If they did, fine, I know how the world works, but word would get out sooner or later and they would destroy their business. I'd certainly go somewhere else and they would lose my monthly income stream. I pay for email.
Gmail -> Outlook forwarding iCloud Photos -> OneDrive
etc
I disagree. I've managed to get locked out twice now.
The first time I have no idea what happened. Google just disregarded the correctly completed email-verification and security questions and just said "no". I retried a month later and was able to log in.
The second time, I logged in from an university-owned Android phone. Despite not even being an admin on that phone, Google decided that it would now be my only permitted 2FA method, and so, when I tried to log in away from university, I was locked out.
This counter has reset at least 5 times now...
I'm still holding out for appeal process which can be done ever 2 weeks. But so far pattern seems to be automatic rejection. Also have Google One which should get you live person support, but they basically forwarded me to Youtube support who said they were not trained to resolve issue. lol. Only saving grace is I could take out all my data and intially even that wasn't possible on my main 10+ year old account for some reason. I guess my point is, even if chance of losing account is low, chance of recovering account is even lower.
For reference I've ranted about knowing people who lost Chinese social media access but actually got accounts retored by a person after submitting insincere self criticism. It's not ideal but still much more functional experience than what I'm going through with Google.
I found that migrating and managing my credentials with Bitwarden has brought a lot of clarity and independence. I can now use these credentials with any browser, any mobile platform, and desktop platform. If I ever need to migrate away from Bitwarden I have the credentials periodically backed-up in JSON format, so they can be transformed into any other format.
Not logging in with Google SSO everywhere and relying on plain old username + password credentials wherever possible (+2fa for important stuff) has also been very liberating. Using a good password manager makes this trivial.
Same with email, having your own domain means you can switch providers in an hour or so if something bad happens. It's also worth keeping a backup of all emails in a common format like Maildir; so they can be restored to the new provider even if you lose access to the old account.
Which brings me to the last point which you've probably figured out by now - backups. Keep backups of everything locally + somewhere remote if you can. Backup emails, google drive contents, google photos, contacts, email filters, etc. Everything! B2 or S3-compatible storage is cheap.
I was an early Gmail adopter, and have hundreds of logins that use my gmail address. I'm now in the process of getting sensible and moving all my logins across to a domain I own. It's still using Google (as in Gmail / workspace) - the free edition - but once I'm done I won't be beholden to Google if there's a lockout or whatever. Pain in the ass though it'd be to move mail servers and to lose my archive (well, any bits I haven't downloaded / synced via IMAP), I'll be in a much better position to Do Things if I can just repoint the domain to Some New Email Service in the future.
It's a pain, but I'm doing it. Slowly.
On the other hand logins from my phone protected by a much weaker 6 number pin are never questioned.
With the unregulated private tyrannies that the US tech corporations have become, you have no recourse if some algorithm or someone just nukes your account in some major provider. Your history, your business contacts, even your infra may be gone in seconds.
We still treat the Internet as if its mid-2000s and its still a mostly hobbyist thing with some big business doing their thing elsewhere while the plebs go about their lives in the fringes of some user-run websites and forums. Losing nothing was a problem then. But now everyone's lives, businesses & livelihoods, professional histories are hooked up to the Internet. Its no longer a hobbyist's ground.
Its amazing how corporations that could kill your business within a second have gone unregulated this long. If some company holds the livelihoods of millions of people in its hands, its not a mere business - its infrastructure.
well, the article is just wrong but i don't feel like going into the nuances of how identity works with a bunch of zero attention span web devs but i blame UN*X for this situation by making computers too hard to use (both securely and at all) with contraptions like email and PGP. all authentication should be done with public keys. open protocols require solid foundations which include the user being security-competent. you can layer on the "poor old dumb user" stuff on top of that, for example by letting him have a 3rd party company hold his private key. but again, this article is just wrong and scoped into very specific things people like to "debate" while having no clue about the big picture. it's absurd to even imagine that the web meta (a bunch of dot com boomers who dont give a fuck about anything other than going with the flow and creating solutions looking for problems, and knee jerk solutions to current problems) represents anything about established security engineering literature
I fully agree that it should be made easier. But people have to create the demand for that to improve.
I respectfully disagree. I succeeded in buying my own domain but it was a VERY painful, confusing, and disagreeable experience, which I wouldn't recommend to anyone who's not amongst the HN techie crowd.
And importantly, Google will change things on you. When I set up my account, all there was was a password. They forced everyone to fill in telephone information or two factor, which is a new unfamiliar security practice, leading to more mistakes.
Separate from any blockchain project, we're using public key auth for account authentication, so our site doesn't have the ability to cancel someone's account for third parties.
- Email on my own domain - Ideally self host - Make sure you have backups
I wrote an application to help with the last part: https://thehorcrux.com/about/
Recently my fathers domain registration lapsed and someone bought the domain. We changed the website to a different address and went to change the google listing for his business only to find that someone had also claimed the business. We have tried requesting ownership, we filed a formal 3rd party dispute, and we have requested a domain change. Through all of this we have just been completely ignored by google. I cannot figure out for the life of me how to get someone from google to help us verify his ownership of the business.
Its had a real impact on how many calls he's getting for work and has created financual hardship for my parents and there is seemingly nothing we can do about it.
If anyones been through this or something similar and has advice please leave a comment. Any help is greatly appreciated.
All my domains are registered in google domains, if my account gets locked... will those domains also be locked?
Also, which domain register would you recommend besides google domains?
BTW: google domains is the only service I currenly use with a google account.
I personally use migadu, $19/yr (they have a student discount as well) for unlimited domains, 200 emails in/20 out daily/5GB storage. That's the lowest plan and I don't think I've ever surpassed it (the limits are soft anyhow). I get surprisingly less actual important email than I thought. (I use my gmail for rewards cards, etc)
But, to actually answer you, mailcow.email seems pretty good :)
And regarding failed payments: My registrar at least emails me 30 days in advance, will email in case of failure, and will not put the domain up for sale until after a grace period (IIRC at least a week), during which they will repeatedly attempt to contact you.
Also, even if you can't own it: that's true of self-hosting also and doesn't apply to just purchasing hosting
Best bet is to own your domain name, as you can control that out of band. If Google, Microsoft, Apple screw up, you can fail over.
personally I would pick fastmail.
Instead use your own domain with whatever email provider suits you. Much easier to setup and worry-free.
(It has been a while since I looked in to this, so things may have changed)
The problem with home-hosted email is, as most folks said many times, that an email sent from a non-major provider would be marked as spam at best and dropped at worst.
My personal solution is to use my own domain, but have mail delivered by protonmail. This is an inexpensive option in a Swiss jurisdiction with generally sane laws. I maintain a copy of all emails on my home system, so if I wanted to switch from protonmail to a homegrown solution or another provider I can easily restore the same IMAP state there. And I would obviously keep the same email, so will not need to notify anyone of any email changes.
Specifically, the bridge + Proton Mail combo reuses UUID. It is a known bug, which proton does not see as a big deal (we will fix it; someday; when we care enough). But what this means is that some messages may be mis-tagged, mis-labeled or mis-deleted between your mail client and the server.
I hit it when I was reorganizing my folder structure, freely adding and deleting subfolders from Thunderbird to create the structure I like. Then, the changes stopped reflecting and a fraction of my messages appeared gone. I finally was able to undo it through the web client, but the experience left me deeply suspicious of anything except the simplest operations with local client. And encouraged more diligence with making local backup copies of my emails.
It's very easy to set up, although your mail might get caught in the spam filters of the giants, even if you are configured 100% correctly.
It takes little effort to setup a mail server to receive mail.
It takes a TON of effort to setup a mail server to send mail. Most ISPs will block your IP address, through various services you can get your IP unblocked but it's a slow and very time consuming process. And $god help you if your server ever gets exploited by a spammer. Your IP address will be permabanned by everyone.
It takes more effort to filter out spam
It takes more effort to deal with all the various email-related attacks. Like Joe Jobs [1], and DSN attacks [2].
You have to get reverse-dns setup on your IP which depending on ISP can range from impossible (comcast) to a pain in the ass (AWS).
You then have to worry about backups, firewall rules, server maintainance, power outages, and yada yada yada.
Then you'll get into it and have to figure out IMAP, SIEVE, and TLS. You'll spend more time managing your email server than any other thing you do in your life. You mail server will replace your family, your job, and all your hobbies.
Just buy a domain, pay for FastMail or ProtonMail, and setup or MX records. You'll be much happier.
[1] https://en.wikipedia.org/wiki/Joe_job
[2] https://community.fortinet.com/t5/FortiMail/Email-users-are-...
Requiring a charge would permit upstarts to undercut that fee by other means (e.g., advertising, otherwise selling influence, data gathering to compete with Google or other firms in the area of AI, etc., etc.).
To get a sense of how common lockouts are and how they happen I looked through lockout reports on Hacker News by searching for [google blocked account] and [google locked out]. I looked at top-level stories and the comments on them for cases where people were entirely locked out of an account...
If the goal is to determine some noted classes of account lock-out, then this method might have some merits. It utterly fails however to satisfy answering the headline question itself, that is "how likely is losing a Google account?"
For that case ... you'd need to have some insights into overall Google account creation and destruction, as well as some way of validating outside of Google's own accounts-adjudication process both how and why accounts were locked.
I've had some very rough connection with this by way of looking into statistics concerning Google+ over the years. Given that for a substantial portion of its life, Google were creating accounts on its little-lamented social service for every Google account (Gmail, YouTube, and most especially Android), there were a lot of accounts. About 2.2 billion when I ran the numbers, hitting a high-water mark of about 3--4 billion accounts.
(Again, not active users, for the most part, but registered users.)
I'd measured members and a few other characteristics both in 2015, when the site was still fairly vibrant, and in 2018/2019 after its shutdown was announced.
Among other observations, I noticed that highly active members were among the most likely to not have a valid account when checked later. In particular, I'd found a list of popular profiles and Communities, and found that a large fraction of these were no longer visible at all on the system. That is, one of the highest signifiers for "account will not exist in future" is "account is presently highly active".
I've speculated as to why this is, though I don't know what the specific mechanisms were. Among the options, comparing highly active accounts with little-used or unused ones:
- Highly-active accounts are more likely to cross some red line or trip some automated, or crowdsourced, flagging mechanism.
- Highly-active members are more likely to become discouraged with the platform itself. (That was certainly my own experience, though I never fully deleted my account.)
As to the question raised by TFA: I've been locked out of several Google accounts, though I've succeeded in recovering the ones I cared about. As a result of those events, however, I've also all but entirely curtailed my use of any authenticated Google services.