Live data from Hacker News

I got locked out of my Google account for a month

techcrunch.com

121–130 of 210 posts

Re: I got locked out of my Google account for a month

#121
Few people seem to realize that if you loose access and they restore you access with limited information, then any attacker could do the same.

If you care about your Google, GitHub, Dropbox, Amazon, PayPal accounts the you should sign up for 2FA. Ideally, you should have one-time recovery codes printed and U2F or TOTP when U2F isn't available.

I keep all of my TOTP tokens on my yubikey which also does the U2F magic. And of course I have a back up.

But if you don't care to setup 2FA, well, I can see how it's better for Google to lock you out as oppose to locking someone else in.

Re: I got locked out of my Google account for a month

#122
post #120
post #115

Earlier quoted context omitted.

Just buy two yubikeys.

Why? Instead of 2FA?

You can do both TOTP and U2F on an yubikey.

U2F is much harder to trick..

And TOTP on your phone is likely to get hacked. TOTP on a physical yubikey is a much harder target.

Re: I got locked out of my Google account for a month

#123

Earlier quoted context omitted.

>Like I've said in the past here, if something is so important to you, you need to treat it as such. Which is why you use a password manager and keep a copy of your Google account backup codes in the event you need them.

Google can lock you out of your account even if you have the right password.

That's why you have 2FA, U2F and one-time recovery codes.

Re: I got locked out of my Google account for a month

#124

Funny, I also have an account where I can't remember the password and I've given google three factors of identification and they still won't verify my account to reset the password. I have no PR friends that work with Google, so I'm shit out of luck.

Where any of those factors: U2F, TOTP, one-time recovery codes?

Re: I got locked out of my Google account for a month

#125

Imagine you used a password manager that required memorizing just one diceware phrase then using randomly generated passwords and never got locked out again, that's what happened to me.

If you start logging in over TOR or other sketchy locations, you might...

I would suggest 2FA, if you really care.

Re: I got locked out of my Google account for a month

#126

Earlier quoted context omitted.

I'm currently locked out of a Gmail account I have the password for but Google decided that isn't enough; it doesn't like my IP address and wants me to verify against a phone number I no longer have.

So I guess the diary should include a history of phone numbers. And maybe addresses to be safe.

Just do one-time recovery codes.

Re: I got locked out of my Google account for a month

#128
>use different passwords all the time and I forgot which one I had used most recently for Google.

May in the last weeks this person entered wrong passwords too often.

>I clicked ‘Forgot Password’ as I always had.

Did the journalist reset passwords too often?

Re: I got locked out of my Google account for a month

#129
post #123

Earlier quoted context omitted.

Google can lock you out of your account even if you have the right password.

That's why you have 2FA, U2F and one-time recovery codes.

Isn't a big problem is that they will sometimes lock you out of everything for some behavior they think is bad on just one of their services. You have been denied access. No tech solution to this problem.

Re: I got locked out of my Google account for a month

#130
post #114
post #88

Why don't they just offer some kind of emergency support with a hefty pricetag for these cases? Eg pay 200$ to have an actual human verify your identity? I don't think that would cost them anything and most people in this situation would likely pay any price to regain access..

Why don't you just buy two yubikey and print one-time recovery codes? If you care about it, then lock it down. In many ways there is no good way to verify you, if you don't invest in 2FA. Would you rather be locked out, or have a hacker locked in?

Well, I use 2FA extensively, including for my Google account. However, there are even more vectors possible with 2FA where you lock yourself out of your account (e.g.loose backup codes, phone and access to phone number) which a human could easily solve (verify scan of ID, address proof, phone call, confirm that no activity for X days on the account in question).
Post reply on HN