Live data from Hacker News

Updating our inactive account policies

blog.google

1–10 of 225 posts

Re: Updating our inactive account policies

#2
> To reduce this risk, we are updating our inactivity policy for Google Accounts to 2 years across our products. Starting later this year, if a Google Account has not been used or signed into for at least 2 years, we may delete the account and its contents – including content within Google Workspace (Gmail, Docs, Drive, Meet, Calendar), YouTube and Google Photos.

Note the may. It is not a guarantee that they will delete!

Re: Updating our inactive account policies

#5
post #3

Account handles will not recyclable (for obvious security considerations). So this seems more akin to "permanently disabled" rather than "deleted"

It has been reported that they will not be reusable for exactly that reason.

https://9to5google.com/2023/05/16/google-account-delete/

Re: Updating our inactive account policies

#6
This ... is not what is going on. When I worked at $bigcorp serving billions in traffic, what happened is that botnets would create accounts and leave them dormant for weeks/months/years (thousands of them), then start doing their bot thing. Account age says a lot when it comes to trust (usually) and spam detection. That's more than likely what they're seeing, not 'compromised' accounts.

All this does is tell the spammers exactly how long they are going to be allowed to have 'sleeper accounts' for, the problem won't magically go away.

Re: Updating our inactive account policies

#8

This ... is not what is going on. When I worked at $bigcorp serving billions in traffic, what happened is that botnets would create accounts and leave them dormant for weeks/months/years (thousands of them), then start doing their bot thing. Account age says a lot when it comes to trust (usually) and spam detection. That's more than likely what they're seeing, not 'compromised' accounts. All this does is tell the spa…

I am sure Google of all companies has enough insight into account behavior to conclude this is the case for them. It's not like they can't verify it either: if the account previously had legitimate activity and is now compromised, it's not really a sleeper account.
Post reply on HN