Gmail's backup codes are useless to access account
116 points| Andrew_nenakhov | 7 months ago
So, one sunny day I decided to add standard iOS mail app to this account, and lo, an hour after connection I get a message, that due to strange activity on my account, I need to enter code sent via sms.
Ok, I don't have that phone with me, so I try to log in with Authenticator, and no, no good: 'we are not sure that it is you, enter code sent to sms'. Ok, I dig backup codes, enter them, and still get 'we are not sure what it is you' message.
What's even the point of allowing to set up Authenticator or Backup Codes if they don't do anything?
If there are some people from Google reading this, please, don't reach out to me offering to help. Just change this dumb system.
[+] [-] NearAP|7 months ago|reply
More than once, I was in a different country and tried logging into a workspace gmail account. Google flags it as a strange activity (fair enough) and needs to authenticate me. It asks me to enter the complete address for my recovery email (I do this), it sends me a code to use for sign in (I do this) but it still refuses to sign me and says it can't authenticate me. It says I need to sign in from a location that I've signed in from before.
So, for the period that I was out of the country, I couldn't access my email. This happened each time I'm in a new country. My only work around was to sign in to my email (on my laptop) before traveling and not sign out (for security reasons, I don't like to do this).
Something similar happened when I used a new laptop.
I just don't understand this. What then is the point of having recovery email and phone number if you won't use them?
[+] [-] david422|7 months ago|reply
But then I thought- what if I just try that password to login. And it worked.
So when I thought I had forgotten my password, gmail prompted me for a piece of information that I got correct, and then wouldn't accept it.
I also have another email account that forwards all mail to my main account, but I've definitely forgotten that password, and I have no way to actually get back into that account, even though I've tried. I guess it just forwards mail forever.
[+] [-] roywiggins|7 months ago|reply
Probably not forever:
https://www.npr.org/2023/11/27/1215285876/google-inactive-ac...
[+] [-] nickdothutton|7 months ago|reply
[+] [-] modeless|7 months ago|reply
[+] [-] Andrew_nenakhov|7 months ago|reply
Then, after 2 months, I tried logging in and suddenly it worked.
[+] [-] venusenvy47|7 months ago|reply
[+] [-] SoftTalker|7 months ago|reply
[+] [-] ikekkdcjkfke|7 months ago|reply
[+] [-] mikece|7 months ago|reply
[+] [-] Andrew_nenakhov|7 months ago|reply
The point of my rant was that with modern day Google, TOTP authentication is not enough.
[+] [-] thesuitonym|7 months ago|reply
[+] [-] firefax|7 months ago|reply
>If there are some people from Google reading this, please, don't reach out to me offering to help.
I wouldn't worry yourself on that front, unless you are some kind of celebrity, they don't seem to care that a basic, core function of one of their most popular products can fail in a manner that totally locks people out.
The whole point of the backup codes is to facilitate account recovery, and it's really hilarious to me that a company full of allegedly elite engineers can't do one simple thing.
I point folks to 0365 for the their cloud needs nowadays -- Microsoft does this strange thing where you pay them money for services that works rather well, and office itself is streets ahead of docs. (And if you enter a code... it WORKS.)
[+] [-] gblargg|7 months ago|reply
One reason I regularly use Google's takeout feature to download all my GMail data. Only takes a minute to initiate.
[+] [-] asdfasdf1|7 months ago|reply
[+] [-] mzajc|7 months ago|reply
Needless to say I decided to forward all mail elsewhere. I wouldn't touch Google for work with a 3m pole.
[+] [-] valrama|7 months ago|reply
It's interesting you got that message (via email?) one hour after you successfully signed in on your iphone. Are you sure it was not some phishing email or something? Also are you still logged in on that account or did you get logged out?
[+] [-] adrianwaj|7 months ago|reply
Surely, an AI can check each shut-off account, work out the identity, and then allow the claimed user to send in a picture of themselves holding some ID.... some variation on that anyway. A Gmail employee can do the final checking after voice chat, and the user could even pay for this.
They could ask questions like: Has person X ever emailed you? When did you meet that person? What's their email address?
Also, generally speaking, are voice biometrics ever used? That could work well. "Please send us a sound file of you saying _______" or call some number and speak to an automated checker. I suppose so many companies could get voiceprints by this stage of people they have recorded.
[+] [-] rvnx|7 months ago|reply
"Automatically suspended by Google systems for being at risk"
+ This is an automated message. Replies are not monitored.
https://www.linkedin.com/pulse/when-you-get-locked-out-your-...
Good luck.
[+] [-] Andrew_nenakhov|7 months ago|reply
[+] [-] jbombadil|7 months ago|reply
Please Google let me have a normal TOTP authentication. No SMS, no "open the gmail app on this other device and tap this prompt", no mandatory Google Authenticator, etc.
[+] [-] fauigerzigerk|7 months ago|reply
[+] [-] ChrisArchitect|7 months ago|reply
Ask HN: GCP Outage?
https://news.ycombinator.com/item?id=44605732
[+] [-] bsoles|7 months ago|reply
[+] [-] jonathantf2|7 months ago|reply
[+] [-] reaperducer|7 months ago|reply
Very strange. I've been using both iOS Mail and macOS mail with my company's Microsoft Exchange server for almost a decade with zero problems.
I've also been using both iOS and macOS with Gmail on my personal account for close to 20 years across close to a dozen computers and devices, and the only problem I've ever had is when Gmail suddenly decides to let some company bypass its spam filter.
I think I use Gmail's web interface maybe two or three times a year.
[+] [-] thibaut_barrere|7 months ago|reply
I'm interested in EU-based products first. But they need to handle spam well!
[+] [-] AndersSandvik|7 months ago|reply
[+] [-] BoppreH|7 months ago|reply
[+] [-] lucianbr|7 months ago|reply
[+] [-] delusional|7 months ago|reply
[+] [-] kstrauser|7 months ago|reply
[+] [-] paul-tharun|7 months ago|reply
[+] [-] Tijdreiziger|7 months ago|reply
[+] [-] vouaobrasil|7 months ago|reply
[+] [-] icedchai|7 months ago|reply
[+] [-] midnightblue|7 months ago|reply
i tried to migrate from Workspace to iCloud but dealing with the insane OSX Calendar app which not only does not put anything into your itinerary automatically but is liable to just disappear items from the Calendar randomly, put me off so much i went right back to Workspace.
[+] [-] Andrew_nenakhov|7 months ago|reply
I even dug out my computer that was logged in to this account in desktop browser, and it too blocks access. Crazy.
[+] [-] robertoandred|7 months ago|reply
[+] [-] bpodgursky|7 months ago|reply
[+] [-] Andrew_nenakhov|7 months ago|reply
[+] [-] unknown|7 months ago|reply
[deleted]
[+] [-] tptacek|7 months ago|reply