Hacker News new | ask | show | jobs
by kuschku 3101 days ago
That is correct, I had the same issue.

My account was previously always used in Germany, and then fell into disuse once I migrated to another Google account (to change the primary email address).

Someone tried several passwords for the account from Russia, Google warned me by sending a warning to the backup email, and let the attacker in anyway.

Being in Germany, the reset flow asked me to either

(a) provide the phone number used, prove I control the backup email, and provide the exact account creation date (I was off by a few months, and it failed to allow me in),

(b) prove ownership of the backup SMS, backup email, and answer all security questions correctly (which I couldn't, because the phone number had long been reassigned).

I, desperately, called Google Nexus support (not possible to solve), and even asked people on the inside, who got the account team on it (more on that later). No can do.

In the end, I got the new owner of the phone number (ALDI Talk reassigns phone numbers after 6 months disuse) to help me by him sending me the SMS verification code, which I'd enter, to verify identity, and get the account back.

After I managed to log into the account, I obviously enabled 2FA, secured it, etc, but I also found a new message in the inbox, from Google's account recovery team, the usual 'thank you for contacting us, etc' one. They had contacted 'me', after I complained that the account was hijacked, by writing an email to the account, and talking with the attacker. Who obviously said there's no problem.

1 comments

>> I'm confused, so you are answering every single security question correctly and you age logging in from your usual location without any kind of Tor/VPN/etc. and you still have no way to access that account?

> That is correct, I had the same issue.

> the reset flow asked me to either (a) provide the phone number used [...] or (b) prove ownership of the backup SMS [...]

> (which I couldn't, because the phone number had long been reassigned)

But this means what I said earlier is not correct, since you are not answering all of their security questions correctly.

I managed to successfully complete the (a) flow, but it was considered not enough, due to the different IP, and minor inaccuracy with the creation date.

I later managed to successfully complete the (b) flow due to the SMS.

I believe Google isn't using a binary definition of success, but a confidence interval of how sure they are you are the actual owner - if they are reasonably sure you are the owner, less questions need to be solved, if they are reasonable sure you are not, they cancel the flow before you even have a chance, and if they're unsure, they ask you more questions.

On my first attempt, I got over a dozen questions to validate myself, later on, I got told "sorry, we don't believe you" after already one question.

> I managed to successfully complete the (a) flow, but it was considered not enough, due to the different IP, and minor inaccuracy with the creation date.

That's exactly what I mean though. You didn't answer their questions correctly. It wasn't just due to your location/IP; you put in the wrong date. (It's quite funny/ironic that you are also answering my questions incorrectly and yet insisting otherwise. While I sympathize with you for the actual problem, it doesn't help anyone sympathize when they see facts being twisted!)

> you put in the wrong date

There is no "wrong" or "right" date for Google. Google's support says to input whatever date you remember, Google will judge it as neither "true" or "false", but based on how close you are, and (this part is now speculation) combine that with other factors.

> There is no "wrong" or "right" date for Google. Google's support says to input whatever date you remember, Google will judge it as neither "true" or "false", but based on how close you are, and (this part is now speculation) combine that with other factors.

I'm sorry but you're not going to win over anybody like this. They asked you for a date, they potentially gave you some leeway for error (or not), and you gave the wrong date. Evidently your error was too high for them to overlook. You could argue they asked a bad question or should have given more leeway, and people might actually sympathize with you there, but relying instead on pedantry like this does not help.