Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Big tech companies locking you out of your own stuff is an underrated threat vector.

I recently had a similar debacle with my Google account when I was travelling out of state and lost my phone. I needed to access my account quickly and fortunately knew my password and had added my partner's phone number as a 2fa method for exactly this kind of scenario.

Well when I went to log in Google took it upon themselves to disable that 2fa method, because it thought there were more secure options available. Except there weren't because I was far from home and all of my other devices!

I was pretty shocked that Google would change my security settings without any notice to me and confirmation on my part.



I've lost 2 different gmail accounts, apparently due to Google deciding to change or not respect my security settings. It's hard to say for sure. Meanwhile I still have a Hotmail email address. (This isn't me saying Microsoft couldn't cause similar issues, but I've at least been able to get things fixed through support in the past.)

I'm of the same mind that providers can be underrated risks, because it doesn't always cross people's minds that the provider could be that seemingly incompetent. It's certainly a potential situation to consider when dealing with companies that have poor support. And unfortunately, not all of them have great support or self-service tools like account recovery codes.


I’ve opted for a backup phone on a $10 line to always have SMS if necessary for 2fa. I don’t take it outside.

Quite frankly I need to make a stronger commitment to memorizing three passwords for life.

But to your point, yes I have critical apps where the main threat vector is being accidentally locked out.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: