|
|
|
|
|
by kccqzy
1405 days ago
|
|
And where do those bulk Google accounts come from? Compromised accounts due to weak/leaked passwords, without 2FA. What does Google do about them? Making it harder to log in to dormant accounts from new devices and locations. What's the result? Periodic HN complaints on someone unable to access their decade-old dormant account, or an active account with a truly forgotten password, etc. Anti-abuse is hard. Damned if you do something, damned if you don't. |
|
For dormant account reactivation, they can ask the user for lots of details that are in the account. For example, "please type in email addresses of as many people as possible that you have sent emails to from this account". Which cities have you previously logged into this account from?
All info would be optional, but the more the user provides the quicker they're going to get in.
When the user has provided enough information to be fairly sure that it's a real user attempting to login, then start a 7 day countdown. During the 7 days, contact the users top contacted email addresses and ask them to reply confirming the user is trying to reactivate the account.
Hire attackers to try and break into old accounts, and use their input to find the likelihood of each type of information being correctly given by the real account owner and an attacker.