An Example of a Sad Google Account Recovery Failure and Its Effects
lauren.vortex.com
lauren.vortex.com
The thing is that at scale your “edge” cases are still millions of people. Companies love the benefits that come from scale, like having a billion people use their service, but they never seem to be capable of handling the other parts that come with it :(
Maybe Google had some of that savvy and that's why they instituted "Don't Be Evil".
With all the supposedly smart people and resources that Google has, you'd think they could somehow figure out how not to be the cause of marginalizing people while dismissing them as "edge cases".
Its possible there's more of a business reason. Was it in response to censorship in repressive countries, or a response to concern about tracking, data etc.
I’m sure that you don’t see people looking out for users for the simple reason that the money guys won and the way you get rewarded is by viewing your customers as cattle.
Very simply, Google and the like should be required by law to have customer service adequate to support user needs in every language they operate. Problem solved.
In all seriousness, how does it even make sense to regulate expensive customer support for a free product?
If you do, you may not have any free products anymore. But perhaps we'd be better off having decent customer support with no free products.
As for paid products, it does make some sense to have some minimum customer support, but I'll be surprised if there's a proper way to word the legislation to achieve what we want it to achieve.
Such legislation isn't theoretical or difficult, India already has their new IT law rules:
>The IT rules 2021 provide for creating avenues for grievance redressal apart from Courts and ensure that the Constitutional rights of Indian citizens are not contravened by any Big-tech Platform by ensuring new accountability standards for SSMIs.
>During the extensive public consultations on the ITRules, the Minister of State for Electronics & Information Technology and Skill Development & Entrepreneurship, Shri Rajeev Chandrasekhar had articulated the stand of the Government that - safety and trust of every Digital Nagrik, and robust grievance redressal system to ensure accountability of all Internet platforms offering a service or product, was an unambiguous goal and that all grievances must be 100% addressed.
>The Grievance Appellate Committee (GAC) is a critical piece of overall policy and legal framework to ensure that Internet in India is Open, Safe & Trusted and Accountable. The need for GAC was created due to large numbers of grievances being left unaddressed or unsatisfactorily addressed by Internet Intermediaries. GAC is expected to create a culture of responsiveness amongst all Internet Platforms and Intermediaries towards their consumers.
Not only this, but most banks have to be members of a consumer arbitration body, or need to be overseen by an ombudsman.
But this still wouldn't stop any bank from using their contractual rights to terminate a relationship if it may be unprofitable or risky to them.
And to be blunt: Considering the vital nature of email to modern communications and livelihood, if free email cannot include a method to regain access, free email should not exist. The amount of damage Google just not caring about people's problems causes is immense.
We actually do need to demand customer service for free services.
They're exploiting our information, and using the fact that they're exploiting us "for free" to give nothing back.
Problem solved then. Companies giving away things "for free" is the original dark pattern.
It makes sense because email addresses have become the defacto gateway to our entire digital lives. Losing access to an email causes significant financial and emotional stress. It should be treated like an essential utility. There needs to be a minimum level of service even if the product is free.
Truth. People using Gmail can pick one of the options below:
A) "If you are not paying for the product, then you are the product"
B) "If you’re not paying for it; you are the product"
It seems instead that they just don't even want to touch it.
I once lost a Google account because of their "the password is not enough, we'll randomly decide what is" policy. It's very unpleasant to get to that "make another account" page, and realise it's all gone.
I'd have happily paid money to go through identity verification and so on to get it back. Its sad they're just leaving this money on the table, hurting both themselves and their customers.
I can't believe I'm writing this, but this is where a middleman could help. Companies can pay a fixed subscription to become "Google Gold Partners" and get privileged access to tech support resources. Users with issues don't pay Google directly, they pay those companies to solve their issues with Google products. In this way Google is still incentivized to solve problems as quickly as possible.
And that’s why this happens.
I always have a failure with Google Fit data, which reports 'Service failed to retrieve this item' on the same JSON file every time. I assume this is something corrupted at their end.
It's not that uncommon for my exports to intermittently show failures with other services -- for example, my latest export, taken on April 20th, also failed to include one of my YouTube videos, with the same 'Service failed to retrieve this item' error. That video is usually included successfully, so I'm guessing this was a glitch.
Nothing major, but I can well believe that others also experience regular errors, although I'm sure we're in the minority.
You just click the boxes for the services you want, it e-mails you when it's ready minutes/hours later, and you download the file(s) at the speed of your internet connection.
Considering it has to zip up many gigabytes of data from various sources, it works at an entirely reasonable speed.
The idea that it's too slow to be of value is a reason not to use it makes no sense.
Do you just not make backups of your data at all, because backups take hours?
POP3 is good for use cases where you're rapidly migrating out and you want to wipe the messages clean, server-side. Or, if you believe the server will play hijinks with your messages or folders in some way, POP3 will give you a snapshot from time of download.
There are now email addresses of some friends from my youth (before I wised up and stopped letting my Google account hold important data) forever locked away where I can't get to them. I'd probably have to work at Google to have any chance at all of recovering.
Scroogled indeed.
When the account is locked out, after a set period of time, Google can do whatever it wants with such data without limitations. The number of locked out accounts, in which Google has and could totally and fully exploit, is likely staggering and beyond what many can imagine.
So I kind of find it strange that I use Google services extensively, and yet I can't recall ever receiving a reminder of that kind. But maybe other people are?
Since Google seems to anecdotally make it impossible to recover an account if you don't have access to your old phone number or another logged-in device, it seems like it should be a bit more proactive in ensuring things like a phone number are kept up-to-date?
Obviously that won't help when people don't touch an account for years, but it would help in cases like this story, where people actively use an account on a device for years but without ever having to regularly put in a password.
I get prompt to verify my recovery email ~once a year. You guys don't ?
So stories like this make me assume that Google isn't sending them out enough. But maybe it does? Then is there a question of people's responsibility if they ignore them?
I however don't have access to the associated phone number. Google won't let me log in...
This also applies to microsoft. Except Microsoft also asks for PII (name, dob, country, gender) But they still want the old phone number
Seriously though, even apple does this - where they periodically ask you for your pin/password on phones with fast biometric logins every 1-2 weeks as a memory refresher.
For google: I think they should do a memory refresher too. Once you've confirmed that you remember it, they can stop bugging you for some time. And if a logged-in user can't remember it, then don't log the user out, give them time to save important things.
Do not use Google for email. Just pay $5/mo for an email service that won’t ruin your life for no good reason.
Just because you're paying doesn't mean you won't get into these situations.
A friend of mine has encountered this with the TOTP authentication code method. During a move from the US to Europe, they lost their phone. Google let them log in to their regular account no problem, but a second account they use infrequently for a social group got locked out when they tried logging a month after the move. The TOTP secret key string is stored in their password manager and Google doesn't say that the password or TOTP key is incorrect, simply that "for your security, you must complete an additional step" by confirming in an app they no longer have.
Maybe I have been doing IT for too long, but knowing the username, password, and any[0] second factor should always be enough. Surprising users with something else, that they might not have, is unacceptable.
0 - I'm willing to forgive if a second factor was recently enabled; maybe the scammer got in and added a new phone number or backup email account or generated emergency access codes. But, configured more than 14 days ago? Must work.
Next time I visited the city I usually logged in from years ago (i had moved), it worked no problem.
Add the google account to an old android phone you don't use (maybe even an emulated android would work) and it skips all the verification stuff simply because it's on a phone. That way you can keep it logged in and change things even if you can't log in via a browser.
So the account is "dead" to you, but not necessarily to Google or at least not until they extract what they want from it (and have sold it to whoever).
It's data on their servers that they control, that no longer has a user. The data then can fall into any of the categories mentioned above, to include the possibility of transfer to 3rd party entities. That they may eventually delete it, is different from how they may have used it or to what entities they may have sent portions to.
And yet Google keeps trying to log me in using it.
The prompts went away when I explicitly removed it as a sign in option.
I also had to explicitly disable "skip password when possible".
Should it not? Accounts get "blocked" because of reasonable suspicion that they're compromised. It's not just something they do to annoy you. The overwhelming majority of these situations are surely just password attempt exhaustion. You or someone else tried a little too hard to log in with a bad password.
So... your solution is to disallow that security layer for people who have typos in their emails and never went through the recovery process? That sounds like it's going to hurt and not help.
I mean, yes. It sucks to lose access to an email account. It sucks immensely more to be hacked. And to some extent those requirements are in conflict. There are tradeoffs to be made.
Or more likely an automated unreasonable suspicion
> Should it not?
Yes, it should never ask you for a confirmation that is impossible, this is a simple nonsense of design. Also, months is not a useful tradeoff
There are of course no details on how exactly the iPad died, and it's possible it's been thrown away already, or that it has been remotely disabled, etc.. But I'm very sure that the iPad can be repaired, or at least that the data on the iPad can be recovered. If the problem is that it doesn't "turn on", maybe spend a couple hundred dollars and send it to e.g. Northridge Fix.
Apple has forced app developers to upgrade their apps, which has revoked support for older iOS versions.
I ran into this over Christmas when trying to help someone who had been using an old "The New iPad" (I think the iPad 2) but had lost the charger cable.
We charged it up, it powered on and reconnected back to their wifi. They had to re-sign in to Apple, but was unable to install any of the Google apps.
Now I would absolutely use a password manager.
And your email should be on your own domain.
Underrated comments, right here. I use login with Google for nonessential things, and own my email domains.
The only things I'd add are that you should own both your email domain and the domain for your recovery email, AND that you should be backup files and photos to another service/location.
(un?)fortunately this is not exactly true. While it's true that some folks do need "extra security", the steps in discussion here are fortunately still applicable for the general population. We as a society have decided (correctly) that leaking your private photos, conversations and data is an unacceptable risk, and punish the companies strongly for it. So companies cannot just make it less secure.
Auth is a complex topic with many gotchas, and there is just no way around it. It's like saying you'd like to drive a car without a license, sure taking the license is "hard", but if you want to drive it's what you've got to do. But only there's a hundred cars actively trying to crash into you and steal your goods.
On what planet do companies get punished strongly for leaking PII? It happens to me multiple times per year and if I'm lucky I get a pittance from a class action suit years later. The executives who raked in huge bonuses cutting security don't get punished and the company stock price rarely suffers beyond a blip when the leak is first disclosed.
There's dozens of high-profile fines every year due to data mishandling from Europe, just a quick search:
> Data protection supervisory authorities across Europe have issued a total of nearly EUR1.1 billion (USD1.2 / GBP0.9 billion) in fines since 28 January 2021, according to international law firm DLA Piper.
"fined Facebook owner Meta META 265 million euros [...] for not better safeguarding more than half a billion users’ phone numbers and other information" - https://www.wsj.com/articles/facebook-parent-meta-fined-276-...
"European Union privacy fine related to data transfer of Facebook's EU users to U.S. servers" - https://www.reuters.com/technology/meta-face-record-eu-priva...
"Luxembourg DPA issues €746 Million GDPR Fine to Amazon" https://dataprivacymanager.net/luxembourg-dpa-issues-e746-mi...
"Manx Care faces £170k fine over patient data breach" - https://www.bbc.co.uk/news/world-europe-isle-of-man-62590514
etc
Edit: Also, just to be clear, the reason I brought up class action lawsuits is not because I think all punishment will result in remuneration for those affected, but because in those cases the class action lawsuits were the only consequence the companies in question faced.
> Start putting CTOs in handcuffs and I'll consider it a strong punishment.
But we are discussing companies, which take decisions to maximize profit for their shareholders; I would also agree with putting CEOs/CTOs in handcuffs under the right circumstances.
security against leaks needs to happen at the backend. security to access an account doesn't protect against leaks of the database. it protects against personal data or identity theft, which is not something companies get punished for
These folks, who need "less security", are the exact same who will tell a stranger their password over the phone simply because they said they worked for Google. Scammers can use data from an email account to write convincing fake communications that lead to folks losing their life savings.
Teaching folks that their data isn't important enough to turn on security, is teaching them to fall into scammer's traps.
Google accounts serve one purpose: if you are trying to use a google resource that requires an account. Example: save some marked places on google maps.
I can't think of other examples. As the article states, google's explanation for their user-hostile policies, is that at their scale, there is no other option. The other option is, provide services at a scale you can support, and if going larger is not affordable, then you are not able to go larger.
Imagine going into a store. You purchase a microwave. You get it home, open the box, and in the box is a dead cat. You take it back to the store, and there's no one to talk to and no customer service desk. You walk back out of the store with your dead cat in the box, and when you show the receipt to the guy in the store, he accuses you of stealing a microwave because the receipt is from yesterday. No, he won't look inside the box, there's another customer walking out whose receipt he needs to check. Then they ban you from all their stores for trying to steal a microwave, because they have you on camera walking.
You write a letter to corporate, and they tell you that at their scale, they cannot have a customer service desk, or hire another receipt checker.
The thing is, there's actually no real reason to use google for anything. You don't need to ban it from your life, you just don't use it for anything that needs an account with data you need to keep. I use google products for maps and to chromecast to my tv. I use it for search. When I get a new machine or browser, that account just gets recreated because I don't bother storing their password or login name. Like for this site.
I've had better luck over the years with google drive to store my documents than a physical backup drive. But the thought of losing access to my account scares me
You have to decide how important your data is. You might divide it into a few categories and decide what you can or cannot afford to lose for each category. For example your password database and family holiday pics are often more important than nearly everything else! Then you decide how much money to throw at all this. It's all a big risk assessment thing.
If you will insist on cloud then please use two of them or one and a local backup system. For really important stuff you can buy a brand that you have heard of 128GB USB stick for about £13 (just checked on Amazon). That's bugger all cash! Buy 10 of them.
Please take responsibility for your data. Use cloudy stuff for convenience but do not lose sight of who really is responsible for it - you.
backups better be local AND remote.
I don’t see how that is better than two or three remote backups?
Do I need to change my strategy?
Example: my work places all our files, including your docs and desktop folder, on OneDrive. There is a local cache, but they don't actually let you do a full sync to local to minimize egress
Example: they replaced my laptop, I had about a TB of data generated on the old one. It's all in OneDrive. I power up the new laptop. I can't just sync everything to it - they disable that via policy. Every time I open something for the first time, it downloads. So if I wanted to say, copy all my crap to AWS. Now I have to Egress the whole thing from Azure.
Now, imagine you have more than a TB. Not arguing either way - just answering the question.
anyways, we obviously both agree that having a local copy is a good idea either way, and i appreciate your additional examples of the problems that one can run into with a remote only backup
I would not dream of actually putting anything useful into a Google account. The most basic of due-dil process should ring an alarm bell enough to awaken the dead.
Entrusting your corporate data to Google is playing a form of Russian Roulette. Do ensure you have local backups. I understand why unprofitable products get dropped by Google - my company does the same thing. However, I'm not running a hyper-scaler cloud. A common misconception about the cloud is that you simply divest all responsibility and shove your stuff into it and all will be well.
Due diligence and caveat emptor.