|
|
|
|
|
by grimskin
2985 days ago
|
|
Well, they definitely do fail at the very core. For the non-enterprise Gmail accounts, there is basically no way for account owners to reattain control over an account if it was hijacked. Google product forums full of people blocked from the recovery of their account by sudo-AI recovery form and all the support they get is repeated "use recovery form" from some kind of "google community volunteers" (or something like that). E-mail account is basically a concentration of personal data and doing so little to protect that negates everything else. |
|
Switching from pseudo-AI to humans isn't necessarily better. I had an attacker successfully social engineer a support person into changing the email associated with one of my videogame accounts which had some valuable items.
Preventing attackers from getting my password is something I can do myself. Preventing attackers from "recovering" my account is not something I can do myself. So I prefer services to have difficult recovery.