Hacker News new | ask | show | jobs
by srwx 1269 days ago
Great so when something like the recent LastPass leak happens and I go in and cycle my password, 2fa and backup codes out of simple precaution Google is going to perhaps mark that all as suspicious and undo it for anyone who might come along and pretend to have lost access to my account?
1 comments

Its a surprisingly risky to update your login credentials. Users do it so rarely its perceived as suspicious even when it comes from known IPs and everything else looks healthy. Given its Google if it goes wrong you loose the account completely. Its insane you have to weigh up the potential consequences of doing the right thing for security but that is how Google has set the system up.
This happened to me on Instagram. I changed my password then logged out to test it. When I tried to log in, I received a generic error. I Googled the message and it appeared to be a “temporary” IP block and people claimed it should work in 24 hours. So I tried the next day, same error. I left it a bit more and came back 3 days later - same error. I then turned on my VPN and was immediately able to log in. So the IP I’ve been using for 2+ years, the one that changed the password, on a known browser, is blocked. But a random IP Instagram has never seen before? No worries!