How I lost access to my Google account today
ehsanakhgari.org
ehsanakhgari.org
I like the products google makes, but their complete refusal to have any sort of customer service makes me hesitant to rely on them for anything beyond what I trust them with now.
[You may be able to allow < 13 year olds with parent's permission, but most sites probably feel that it's too much effort/risk to do that.]
It has happened to me - I lost everything, calendar, email, g+ (which I had not ever updated and had no ToS violations on), absolutely everything.
In the next two days I googled (yes, I did) for answers while receiving automated messages that seemed to indicate I was never getting my accounts back (submitted the form they asked me to, but nothing came of it).
I lost my appointments, contacts, and had business people doubt my veracity, as I'd just given my gmail to several new contacts and their initial emails all bounced.
If I hadn't had multiple friends inside of google I might never have gotten my accounts back, and I heard they weren't even sure what exactly happened other than a confluence of events. I then learned how very very common it is to lose a google account and never know why, and never be able get back anything on them (family pictures, phone numbers stored in contact lists...)
I'm now mostly divested from google and the things I still have there I now have backups and redundancies for.
And she had all of her digital life in there.
She made for herself another Gmail account which she has safeguarded a lot more, but it's still chilling to know that you have no recourse.
Gmail is so convenient, that it's hard not to use it, but I'd pay for customer service.
So pay for it? I'm not saying that it's right for Google to do this, but they do offer that option. With a Google Apps subscription, you get support.
Generally, if it can't be implemented by an algorithm, Google's not going to do it, ever.
e.g. "24/7 Support" meant I was free to sent them an e-mail anytime, day or night. Or I could call the 800 line and leave a message ("Calls are usually returned within two business days!").
When I did get through this way, I had to run a gauntlet to convince the asshole (and he was an asshole) that I'd exhausted every imaginable self service option before having the audacity to call for help directly - even though this was the exact service I was paying for.
Seriously, you'd think I'd called 911 to report that I was running out of milk and eggs. In reality, my accounts had vanished completely. Business accounts, I might add. Not that it mattered to Google.
Like an earlier commenter noted - if you use Google for anything that matters, you'll probably be okay. After all, the odds are in your favor. But if you do get screwed, you get screwed completely, suddenly, and without warning. And that's true of customers and users alike.
a PAYING customer of gmail lost his account.
but still, he is having problem with his account used for gmail, which he pays.
why does he have to pay yet another product to have support for the one he is having problem with?
do you have to buy a 2liter coke to be able to complain that they delivered the wrong toppings in your pizza? makes no sense.
This is the story we hear again and again - you CAN get customer service from Google if you have contacts inside or you can raise a big stink at some forum that Googlers read.
The black box google currently presents makes me uninterested in trusting them, since to do so would present a lot of risk (losing my email) with very little reward (a sort-of-better facebook clone).
On a related note, I'm actually bummed that iCloud is free. I felt better about access to my data when I was paying yearly for MobileMe, and in fact started recently experiencing some issues getting Mail in Snow Leopard to recognize my iCloud account and finally ended up just upgrading to Lion to resolve the issue. (Yes, the $30 OS upgrade is cheaper than the $99 MobileMe cost, and I'm glad I upgraded because I'm enjoying using Lion, but I dislike how easy it is for Apple to say now that it's a free service they're free to stop supporting anything that isn't the latest iDevice or version of their OS if things happen to work out that way.)
In other words, that what we did get, is pretty useless.
The good news is that the odds are on your side. Most people do not, of course, get their account shut down willy-nilly. But if it happens you're pretty much out of luck.
I moved my email over to Fastmail.fm, a subscription email service, around 8 months ago. They've been in the business since 1999 and seem to be pretty reliable. The web interface and price obviously doesn't compare to Gmail, but all the other features are there.
Or: use Google Apps for Domains, so that you can easily switch to another mail service when necessary, and have one machine make a backup with offlineimap.
Seriously, Gmail is free, you really can't complain about something that's free (yes, I know you "pay" by looking at ads, but when you can upgrade to the "premium" service for $50, never have to look at another ad again and get 24/7 phone support, why wouldn't you?)
Their new web interface currently in beta at https://beta.fastmail.fm/ is very nice. I've been using it (the new interface) for few months and don't feel like I want to go back to Gmail at all. (Then again I don't use labels in Gmail, so your mileage may vary.)
And today, you tell me to go to beta.fastmail.fm ... a site that looks like this: http://o7.no/IPvfHo
Note broken images, missing Latest News, and they can't even spell Fastmail correctly (see below "Login to your account"). This does not inspire confidence.
[Off topic: I think FastMail support system is pretty lame; despite being an email service, the only way to contact their support is via... web interface. They have few weird quirk like this but it's not something I couldn't live with.]
https://beta.fastmail.fm/pages/fastmail/images/fmlogo_horiz_...
vs.
https://fastmail.fm/pages/fastmail/images/fmlogo_horiz_320.p...
People need to think things through before uploading all of their stuff to "the cloud." The network is a transmission medium, not a place to keep things. If you own a connected server, that's one thing. But why trust all of your data to some third party who can pull the plug on a whim and leave you with no recourse?
Here's Microsoft's moronic account-recovery procedure for an inexplicably blocked Hotmail account. It's IMPOSSIBLE to follow the directions:
http://farm6.staticflickr.com/5306/5773538918_fa4af1de42_b.j...
There is no such thing as a safe system with one point of failure. No matter what medium you use to store data, you must always have a backup. It's the only way to be sure.
(Personally, I pay the $5 a month for a Google Apps account. It's convenient to let Google host my email, but if something goes wrong, I can always change my MX record and start collecting my own incoming mail again. And, I don't have to block ads anymore :)
http://www.wired.com/threatlevel/2008/03/godaddy-silence
In support of your (and my) point: Local storage is now dirt-cheap, small in size, and spacious. Exactly the WRONG time to start turning your data over to someone else to store "in the cloud."
The plug computer is a Sheeva plug. There is a low power WD USB 1 TB drive connected, power consumption in idle is <5 W.
Gmail should let you download all emails into an email client, but the point people are making about losing access to the address itself remains very valid.
Would be interesting to know if anyone has ever lost access to their account and filed suit in an attempt to get it back. Current MegaUpload case is a bit different, but related.
The anger and rage Google provokes by not letting people log in and access their own data is totally unnecessary. They could just as well let people log in, view their data and receive email but prevent them from sending mail, publishing content, uploading more stuff, etc.
This is not simply about automation or no automation. It's about smarter automation and an intelligently staged response to any suspected issues. If algorithms are to be accepted as decision makers, they have to be gentle and not treat everyone like a criminal as soon as there is some suspicion.
The downside to running such a heavily automated ship is that without countermeasures, a sophisticated attacker could map out the thresholds of your fraud/misuse detection system, and then keep just below triggering point.
On top of that, there are actually situations in which you might want your account to be suspending quickly - ideally before an intruder can cause too much damage or access any valuable information.
Some sort of graduated response is clearly necessary, but the real issue is the complete lack of timely dispute investigation/resolution. And it's probably a hard enough problem to resist automation for quite a while yet.
Edit: This obviously only applies to situations where they might reasonably expect you to be malicious, or someone else to be in control of your account. Immediate irrevocable suspension over some tiny ToS violation is pure madness
1) A suspected TOS violation by the legitimate owner of the account.
Trying to prevent this via obscurity is crazy and counter-productive as people cannot learn from honest mistakes. It also antagonizes people who become victims of bad algorithms. There is no reason why the kind of staged response I outlined couldn't work in this case.
2) A suspected security breach that puts ownership in doubt.
This should be handled by resetting the password and contacting the legitimate owner using contact information on file before the breach. It's really simple.
1) attacker guesses your password or obtains it via phising.
2) attacker changes password, starts sending spam
3) google locks account
When you have arrived at 2), you have already lost the account for good, and 3) is only for damage control.
You should know that Google has no way to verify whether your account has been hacked, or whether you yourself are a spammer; therefore the best thing for them to do is just to lock the account.
I would do it this way:
1) Make sure that only the legitimate owner has access to the account by using previously entered contact data to ask him/her change the password.
2) Check if the suspicious behavior stops, which it will in most cases.
3) If it doesn't stop, put the account in read-only mode. If the kind of behavior may be an honest mistake, explain to the user what happened. Just take that risk, it's going to be worth it.
4) If it's a statistically active user with lots of regular looking data, let a human sort things out.
5) If the issue remains unclear, tell the user to download any data he wants to keep and notify him/her that the account will be closed.
Your option 1) boils down to adding more "passwords" by which the user can authenticate itself, so it's not a fundamentally better protection as they can be guessed by an attacker as well. Requiring a text message confirmation for password changes might be a better idea.
Google has a lot to gain from people entrusting them with their data, that's why they provide a free email service in the first place.
It would be a mistake to think that trust is linear. You can't just treat a few people very badly without risking a major backlash against your business model.
Excellent point.
Btw one easy way to maintain a local copy of all your gmail-emails is to use a mail client (like Outlook or Apple Mail) with gmail. With Outlook, for example, you can easily download and move emails into a PST/OST file on your PC.
The other way is to maintain a non local copy by setting up a forward to another email account elsewhere. That's automatic and doesn't require downloading to your local machine and happens in real time.
e.g. paul@wvenable.me would be aliased to paulharris@gmail.com at your DNS provider.
Then you only ever pass around wvenable.me addresses. If you get a good provider, they will give you unlimited free aliasing (though they may not allow catch-all address for free, which redirect anything@ to some default address, due to spam potential).
Combined with monthly backups via IMAP or export from your actual email providers, you will never be dependent in either identity, contacts or content with any single provider.
Needless to say, all of the above is trivial to setup for a typical HN'er.
And, by the way, you can always use Mozilla Thunderbird
http://support.microsoft.com/kb/296088: "This problem occurs because the .pst and the .ost files have a 2 gigabyte (GB) size limitation, and the error message occurs when it is exceeded. "
Available on all sane platforms. Linux distros natively, Mac OS X (you might need to go to DarwinPorts for the software), and Windows (via Cygwin).
Note with offlineimap, changes on the server (e.g.: mail deletions) will be reflected on your local archive when re-synched. If your goal is archival, you'll want to copy the local mail you want to save permanently elsewhere.
Here is what I recommend you do (before getting locked out):
1. Use your own domain for email and host it on gmail (free) - do not use yourname@gmail.com, but yourname@yourdomain.com.
2. Create a secondary email account and have your primary account forward all emails to it.
If you get locked out, your account still accepts emails. I believe that forwarding still works as well, though I haven't been able to verify it (need to get locked out again...).
Then either respond from your secondary account, or change your mx records to point to another service, or even to your own temporary SMTP server.
It's not a complete / ideal solution. You still don't have access to emails you sent (could be done using IMAP, but I didn't bother) and to other Google services. But it might be OK as a temporary solution until you get your account back.
If you run and maintain your own SMTP server and it goes down, you won't be able to send email.
Everyone else will still be able to send email to you, and it will be delivered to you, and you'll be able to read it.
Now, if you break Postfix or something on your server and start bouncing emails then you can be in trouble, or if you mess up the DNS somehow.
But generally running your own mail server is a set it up and leave it alone type of affair. Any junior level hacker can cobble one together with guides online and have it up and running with no problems in a few hours.
Generally, running an SMTP server is quite a responsibility: not losing mail, not being exploited to send spam. What matters is not so much that you can set up in a few hours, but whether you want to take on that responsibility.
I used to own and manage my own mail server when I had to do it for my business back in the day. I had to be up to date in all involved email server management and its perks anyway, so it wasn't a lot of extra work. Now it would be. For a normal email user, it would be a nightmare.
I'm the kind of person who's very disrupted by having a ton of small tasks in the background all the time. Maintaining your own email server adds a bunch of them, even if you are already knowledgeable (keeping your domain(s), storage & redundancy, having to maintain a server with good uptime and with a lot of security concerns - it's online and it broadcasts its IP in headers, it's immediately spotted as running an email server and targeted to be made a spam-relay or worse).
If you're not even knowledgeable about it, the amount of stuff you need to learn and be familiar with is ridiculous. Maybe they don't even occur to you off the top of your head now, but the amount of little things one learns over the years about server maintenance is massive and a lot of it is absolutely necessary to run an email server with guarantees. Having to "insource" all that shit work is something I've been trying to avoid but I'm afraid I will have to do. I rent, this means sometimes I have to move and keeping servers 365/24/7 is a problem. Typical home connections are rather shitty for an email server in terms of uptime - you'd have the occasional email silently not arriving (depending on sender retry config) and also the occasional bounce (server coming back up but not properly - happens) and that doesn't look good for serious communications this day an age. And like that, a large number of concerns both particular and common to each email user.
Having backups (also involves shit work but not as much) mitigates the problem but for some of us, simply to stop receiving email at a certain address for a couple of days can cause a lot of trouble.
2) You value your time. Some people don't, it's not really worth arguing this point. But it is a reason running a mail server is a bad idea for most people.
And #2 is just wrong, sorry. I spend minutes a week doing anything at all related to maintenance on that box (I use it far more regularly for productive purposes, though). If you can handle running a linux box from a console, you can learn to do it too. Or don't, it's up to you. But telling me I don't value my time is just out of line.
>> I've been running my own for 13 years now (plain old postfix and dovecot on whatever linux distro I favor at the time).
For those of us without the experience of 13 years running postfix and dovecot (and spamassassin and writing perl filters), there will certainly be at least some time investment. That's what I was talking about: the price in hours to go from zero to competent. You may be too competent by now at email hosting to realize that it would not be a minutes per week affair for most people to do well.
Obviously if it works for you, great. Interesting to note that you started running your own long before GMail; the calculus of starting to self-host is different now.
Re #1, you should lend your spam filtering tools to Yahoo! In all seriousness, a handful of unwanted messages per day would be a dramatic improvement to my Yahoo! inbox. Whatever they are doing over there is not as good as what you're running.
I sometimes wonder if GMail lets these through for certain people, and relies on the "mark this as spam" button as some sort of mechanical turk...
And MX records don't support an alternative port to my knowledge.
Unless you shell out for the "real internet" (the business package) it's like fighting an uphill battle to run your own servers anymore.
Ahhh the Internet... I remember that.
What gets me is that email was one of the first peer-to-peer networks, and 90% of people, including myself, on residential links, are excluded from using it as designed. It seems more wrong to pay to solve a man-made problem. Free webmail is "good enough" if I'm just going to pull my messages offline and use it as a relay...
I remember there being "more internet" on my 28kbps modem... Port 25 and 80 worked from home, SMTP servers didn't reject mail from anyone on a residential ISP. I actually wrote a letter to my ISPs when they started blocking SMTP (yeah, I'm THAT guy)... Their argument was "but spammers," and they wouldn't make an exception for 1 out of a thousand. I even wound up switching providers over it. A year later everyone was doing it and there was no stand left to make. Spam is our "airport security" scarecrow (among others... copyright, porn, etc)... We'll undo the whole thing if we have to.
And so Gmail it is, until Email 2.0 comes around, and is new enough not to be intentionally broken, or I decide to shell out and license the real internet from my oversubscribed ISP that throttles uploads so noone can offer new and interesting services using their networks that might compete with them.
Don't get me started on QoS -- the neutrality killer... (We moan when people throttle BitTorrent, but when it's called QoS, it's "Smart"!)
Behold, de-evolution.
claps the disappointed clap... of the disappointed :o)
Why does it matter? You're not storing data on that server or anything, so the cost to leave is negligible.
Honestly, I'd rather just pay a monthly fee for the damn thing if it meant a unilateral action such as an account suspension wouldn't happen without prior warning. I'm serious Google. It's a good service. Take my money.
I don't know if you can port an @gmail.com email address in, but if you have your own domain for $5 / user / month you get phone + email support.
Also, I'm not positive, but I'm pretty sure it's standard to set it up on your own domain and forward data from any gmail.com addresses you care about.
Are there any good alternatives? Are their any alternatives at all?
My guess is that it was more like 300, and cc'd to a bunch of external addresses such that it looked like spam.
So macspoofing: what did you have to do to get the account reenabled?
Believe it. It happened.
>what did you have to do to get the account reenabled?
Waited a few hours, and it was reenabled automagically.
I bet that uploading a bunch of files all at once could trigger that lock.
For everyone else, I'm using backupify.com to backup my Gmail and Google Contacts (and sent tweets, for some reason…)
I lost my adwords account one day, I wasn't even using it at the time. From what I gathered from support I lost it because a year and half earlier I had run two ads that were against the TOS. These ads were running for a total of 4 hours BTW and were of course approved by Google before going online.
I have no idea how they tune their algorithm so recklessly. I posted about it on HN before and someone brought up the idea (from experience) that the landing pages I used (I did not own the landing pages) were changed during those 18 months to something that is against the TOS and my account was flagged because I had used them in the past.
- If you pay $50/year for Google Apps, you can use your own domain name, so you can change your mail server without changing your email address, and you also get access to customer service from Google. I have Google Apps and the one time I contacted them, they got back to me right away.
- Just like it's a good idea to backup your local computer, it's a good idea to backup the data in your cloud services. There are numerous options. Backupify, CloudPull, and ThinkUp (thinkupapp.com) are some which come to mind.
I use Apple Mail for backup. The only issue is the TTL setting for the DNS MX record. Some domain hosts set this to 24 hours, which means it may take up to 48 hours for all mails to get through after you switch to a different mail server.
A backup of my local data is semi-automatic by running a shell script that rsync's everything to my USB HDD. I like local better, I think.
On a side note, it's sh*t like this that make law makers create crazy laws that would stop poor support like this.
I for one would almost want government intervention to make sure when cloud services cut you off, they don't take hostage of your data and history too. I recognize it's a terrible/horrible solution, but if the companies themselves can't do the right thing, government mandate would have to be next. Cause in this case, it's not like we can vote with our wallets to make it go away when the stuff is free.
Also, imagine the number of jobs Google could create if they hired and trained a support staff for all their products? There's a lot of stuff that would still benefit from a human touch.
We tell people they need backups. With a TOS like "we can shut you down at any time for any reason", you definitely need backups for Gmail too if it's important.
GApps backup 36 bucks a user a year.
What would be racing through my mind was my account hacked, as if so maybe other services I use be hacked.
Or did I possibly break the terms of service? If so, what may have been the justified reasons for me doing so, or Google's reason for preventing me so?
That's where full communication with Google would be so essential to remove the ambiguity and resolve what may be a bigger question at hand.
You can take back your power by using smaller corporations for essential services such as email, making sure they are NOT located in the USA (should be obvious, but I feel I should reinforce that you cant get privacy in the USA).
Then again, if you use Google, perhaps you dont care about privacy in the first place.
And no, having ads does not mean that you are paying. Someone else is paying for those ads, if anything they are sponsoring your ability to enjoy a free service devoid of customer support.
Note, however, that the latter will only work if your account hasn't been accessed in 24 hours. If you have 2factor enabled, make sure you have backup codes printed as well.
- getting a dedicated domain
- getting either google apps or another web mailer
- setting up new email address for 50+ services
- finding some local client, doing backups and what ever
mail account migration is a lot of work ...
Good luck gettings yours back, I'm going to back up mine this weekend!
Google's support sucks and they desperately need to improve it. But people also need to back things up, dammit.
It's well known that your data should be redundant, this is one of those 'I didn't make a backup' posts.
If you use multiple operating systems, or you want to use a high quality open source client, best choice is Thunderbird (this is what I use).
On Windows the default email client is Outlook.
On Mac, iPhone, iPad the default email client is named Mail.
All of the above email clients will save your emails from Gmail on your HDD.
Every email I've received in the last eight years is stored on my MacBook, indexed in Spotlight, backed up in Time Machine, and available for offline reading whenever I need it. If my Gmail account was suspended tomorrow it would be a nuisance, but I would not lose any data and could recover from it quickly enough.
I've found it very helpful.
Many have their adsense and Adwords linked to suspended Gmail accounts too. It can cripple their business.