> Even if the risk is low, however, maybe it would still be better to switch to something else that is even lower risk? The problem is that security and policy lockouts are something you can find with any service. For example, in HN discussions people will often recommend Fastmail or Protonmail, but they've had their problems too (FM: 2017, 2020, 2022, PM: 2018, 2019, 2021). Especially given that these are much smaller services I'm not convinced that the risk is lower there. Any system is going to have to handle this sort of problem, and you're not going to find one that never has false positives.
Good breakdown for this person's use case.
I disagree with the conclusion above though. My experience (as a person who handles technical support around these issues, for customers of Gmail and more specifically ATT/Yahoo/SBCGlobal) is that many people that get locked out of their accounts do not understand all the options available to them to regain access. Also it appears, to me, that at least for Fastmail, their security protocols are a bit more friendly, less strict about how the security is applied (I.E not spamming customers to use the security methods, changing the methods willy/nilly without warning). Also Fastmail sends an email to your mail email account if you accidentally trying to use your main account password in an app specific use-case, I.E makes it easier to understand how the security measures are being applied.
Also the security measures implemented by providers that you pay for, appear to me, to be designed to be customer centric, rather than trying to create a blanket one size fits all approach to security that I feel google tries to implement (because they have so many customers). My meaning about this is that the control of the security options appear, to me, to be more in the hands of the customer to implement how they see fit, where as google security measures appear to be implemented from a cover our assess approach and not really designed for the customer per say.