Hacker News new | ask | show | jobs
by judge2020 1583 days ago
Google doesn't get social engineered into handing over user accounts since maybe a few hundred people have any access to the Google Accounts system proper, less so for the gmail.com organization (Workspace Support can help with recovering an Admin account in an org). Introducing a way to retrieve an account via human intervention makes the chance of someone taking over a Google account via malicious social engineering, incl. faking national ID cards, non-zero. In fact, i'm sure tons of people have been able to take over accounts using account recovery[0] where it'll ask you things like "when did you create this account" and "what was the phone number you put on the account".

0: https://support.google.com/accounts/answer/7299973