Top
Best
New

Posted by zenincognito 4 days ago

My Google Workspace account suspension(zencapital.substack.com)
369 points | 221 commentspage 3
bradley13 3 days ago|
With phone numbers, you can move from one carrier to another, while retaining your number. This helps with competition.

We need the same for email.

Sure, it may not work with the ancillary services, but keeping your email address would solve a lot of issues.

phpnode 3 days ago|
I mean, you can do that already, you use your own domain name and can then change email providers at will, in theory.

But maybe you logged in to your domain registrar through google oauth. If your google account is locked you can't now get into your domain's settings to change your MX records.

The real problem isn't the email address itself, it's all the access that google owns on your behalf. Lose access to Google, lose access to everything.

caerwy 3 days ago||
These kind of stories led me to explore de-googling my digital life. And honestly its been a fun journey and given meaning and purpose to my homelab. 100% recommend. Own your digital life, run local, reclaim the web.
cj 3 days ago||
Using a Google Workspace Super Admin account for your non-admin day to day needs is similar to using your AWS root account instead of IAM users.

In my experience Google Workspave support is very good. I’ve always been able to get a knowledgeable person on a call to debug issues without much difficulty.

But yea, if you’re locked out of your admin account, that’s another story. Very sjmilar to if you get locked out of your AWS root account. It’s a nightmare to recover.

ValentineC 3 days ago||
> Using a Google Workspace Super Admin account for your non-admin day to day needs is similar to using your AWS root account instead of IAM users.

It sounds like the mistake here is not appointing another Super Admin, and making sure they don't use their account for day to day needs. Or just having two Super Admin accounts controlled by the same person, heh.

I can't see how not using one's Super Admin account wouldn't prevent tripping some kind of fraud lockout that's impossible to recover from.

Randomly, I just remembered that I lost a GCP account because I tried logging in from Laos, and they asked me for the front and back photos of a payment card that I used ages ago that I didn't bother making scans of before it was lost. Urgh.

pfooti 3 days ago||
Make a primary super admin (admin@ whatever) and only log into it for admin purposes. Make an actual user (you@) for day to day line of business work. This has the benefit of making some categories of spear phishing and xsrf attacks harder if the account that gets compromised doesn't have root.
ValentineC 3 days ago||
That's what I've been doing.

It doesn't address this thread's concern that a single Super Admin could be locked out with no recourse, since Google's customer support is horrendously bad.

e40 3 days ago||
So you're saying for a simple setup of 1 user, you really need to pay for 2 users. The admin account and the real user you want to use, which doubles the cost.
cj 3 days ago||
In an ideal world, 3 users, because you want a backup admin in case your primary admin is lost.

I don’t love it either, but these are Google’s published best practices / recommendations

rglover 3 days ago||
Just had to fix an AWS account lock out this morning. Why? Despite having a $0 balance and payment info on file, until I set a budget (a new feature per their UI), all of my Cloudfront-hosted files were just unavailable on my business' site (I Cloudfront all static assets so all images, fonts, etc were just broken all of a sudden).

These are the limits of scale. Too big, too complex, and not enough skilled people to maintain and/or support it. And our hubris as humans prevents us from accepting it. Why? Why can't we accept smaller but more functional things/systems?

We don't have to live like this.

Fire-Dragon-DoL 3 days ago||
I discovered this same issue, you are required to have a phone their auth system is bugged me.

I just set up google workspace and I didn't have recovery phone or anything,just password and recovery email. I didn't login for 1 week (life stuff). When I came back it allowed me to login but didn't allow any admin stuff saying it didn't recognize me and that I must use a known browser.

Well, that was the only browser I logged in with.

The solution was a weird thing where I was able to add phone recovery and authenticator, but then had to wait 2 weeks (couldn't use it). After that I performed authentication as usual.

It's horrible.

vednig 3 days ago||
Been there done that, none of it works, till this date my YouTube account is suspended and they can't do a thing about it.

Google Drive & Workspace are their most poorly designed products with the shittiest support ecosystem. Google would rather bleed money than work on it.

That's one of reason I started DoShare Personal Cloud[₁]

[1] https://getcloud.doshare.me

fortran77 3 days ago||
At least he owns his own domain and can eventually switch over. A few years ago we decided to switch our personal emails from gmail accounts to domains we own (though the email is still handled by google.) This way if we ever lose our google account, we can switch the MX and be able to get all our recovery emails, bank second factors, password recoveries, etc.
l72 3 days ago|
They could switch their domain to another email provider and start getting emails, which is great. The problem though, is they also used their Google Account to log in to all the 3rd party services (payroll). I have no idea how you would get back into those services. Some _might_ let you switch off the Google Sign-in SSO, but I imagine that is a headache.
drnick1 3 days ago||
Run your own email server, and give Google the middle finger. Letting Google own your email, and freely spy on your communications is insane. I think this incident clearly demonstrates that you cannot leave critical infrastructure like this in the hands of a third party.
myultidevhq 3 days ago||
The 40+ hour window with no human contact is the part that hurts most. Small things that would be fixable with a 5-minute call compound fast when payroll is missing. Do team members still have access to their individual accounts during the suspension, or is everyone locked out?
More comments...