12/25/2025 at 10:29:37 PM
I wish they'd let me recover my original -- I lost my TOTP generator, and the codes I'd written down in a paper notebook were rejected. I even hunted down the electronic copy in case there was a transcription error -- seemed like some failure in their systems was causing me to lose access despite having followed proper procedures.Lost a decade and a half of correspondence dating back to my teenage years. I had imported my phone number I'd had since I was 16 into voice, and it doubled as my Signal number. I even had a Gsuite subscription so I could use their (admittedly decently) UI to power my firstname @ lastname dot com email address.
I will never use their services again, I was really digusted by this failure.
by firefax
12/25/2025 at 11:15:21 PM
I had something kinda similar happen to my hotmail account. While I didn't lose access to it, I lost more than a decade of correspondence dating back to my teenage years. The reason was that Microsoft at some point required you to "login" once every 30 days. It seems they only counted logins through their web interface or something like that, so even though I was receiving emails daily, I didn't trigger a "login" in their system. They then deleted all my emails, but I could still login.by macrolime
12/25/2025 at 11:53:07 PM
This happened to me ten years ago. A while later they did the same thing with my Minecraft login that I had purchased before the EULA was in place; I’ve avoided their services like the plague since then.by lurk2
12/25/2025 at 10:44:33 PM
I still think about my lost address that I obtained when Gmail was invite only. My family still occasionally CCs it and it drives me nuts, I would pay money to at least have it shutdown so they don’t think I received an email. I had email forwarding to another address when stolen and immediately after it was stolen it had the weirdest messages, I tried multiple ways reaching out to google and it still bugs me I was unsuccessful. I’d love the their of my account to at least have it shutdownby fosco
12/25/2025 at 11:40:09 PM
Maybe you should send it enough mail to fill it up and the it would reject emails? Send a bunch of emails with large attachments and avoid getting marked as spam.by gleenn
12/25/2025 at 11:00:39 PM
I got mine when it was invite only too, I had it a very long time.I use protonmail now -- I think the "free" model enables providers to shrug and go "hey you don't pay us" (if there is support at all -- I've never been able to speak to a human about this issue)
by firefax
12/25/2025 at 11:16:35 PM
>I think the "free" model enables providers to shrug and go "hey you don't pay us" (if there is support at all -- I've never been able to speak to a human about this issue)I also have paid services a lot of money where customer service was nonexistent until I did a credit card chargeback or raised an issue with government regulators.
I'm trying to figure out exactly what I want to push my state legislature to encode into law with regards to customer service minimums that would cover anyone doing business in the state, free or paid.
by colechristensen
12/26/2025 at 4:36:59 AM
I'm in the camp that paying makes you a customer. Inversely using a free service makes you a user, not a customer.And as you correctly note, there I'd no "user service" department.
You can of course push for any law you like, but I expect laws protecting "users" to be toothless. Basically the TOS will boil down to "we can do anything we like" - which I guess is more or less what they say now.
I find it helpful to think of users as distinct from customers because it let's you understand the provider company motivations.
For example, Google's customer's are advertisers. Hence they cull services not conducive to advertising.
Most startups see VCs as the customer. Their business model is to sell shares to VCs in round after round. Seen in that light their attitude to users is rational and users only exist as props to VC sales.
VCs (and founders) are chasing an exit, which is usually acquisition or aquihire. Your use of the service will thus rarely survive the exit.
These are not things to be outraged about. They are all completely rational and predictable outcomes. When you use a service, these are factors you should evaluate.
by bruce511
12/26/2025 at 6:01:40 PM
> I'm in the camp that paying makes you a customer. Inversely using a free service makes you a user, not a customer.I agree, but what do you do when a large player like Google kills the competition by making their service available for free? I used to pay for email hosting with good customer support. That company went out of business when free GMail wrecked their business model. I moved to another hosting service, which almost immediately went out of business for the same reason.
Something similar happened with YouTube. It's chock full of ads and/or subscriptions now because they subsidized it long enough to ensure competitors couldn't gain a foothold.
by permonst
12/27/2025 at 4:29:01 AM
Thats not exactly a new question. Netscape would also like an answer.Obviously the short answer, for you personally, is "nothing". You cannot affect either the closing business or Google.
The somewhat longer answer is that there are certainly other mail services that currently exist. So there are still options. And yes, those services will need to differentiate their offering.
[Some will no doubt mention the option to self-host. I did that myself for about 15 years. It's a lot of extra work to do that though.]
Obviously some services (like YouTube) are double-sided. Consumers go there because producers are there and vice versa. But, as you point out, even there you have choices - free with ads, or subscription. (Not that you'll get any "customer support" from Google.)
by bruce511
12/27/2025 at 7:50:53 AM
it's even worse than this.your paid email address would now always end up in people's spam folder by default, because the big 2 don't trust any email not originating from the big 2
by tpoacher
12/26/2025 at 12:24:15 AM
I had this issue with my alternative account. Despite my main account being associated (not by recovery, I think this predates that feature), and most messages being forwaded to my main I was never able to successfully recover the credentials.by valiant55
12/26/2025 at 8:39:58 AM
I had the same issue with my Hotmail address. I know the address and password, but Microsoft won’t let me login. And they ask ridiculous things like, what emails are in the inbox. I haven’t used this address for 20 years, I just want to access the Hotmail address from when I was a teenager.by thiht
12/26/2025 at 9:26:00 AM
Send some emails to the address, then you'll know what is in the inbox :)by jopsen
12/26/2025 at 9:38:02 AM
Haha that’s clever, I will try thisby thiht
12/26/2025 at 10:09:33 AM
>I just want to access the Hotmail address from when I was a teenager.Logging in doesn't solve your problem. It gets way worse after you log in [0]. At least now you still have hope.
by sillyfluke
12/26/2025 at 5:27:52 AM
Gmail is a throwaway email. I lost my SIM and hence can't log in anymore.Never ever rely on Gmail.
by Beijinger
12/26/2025 at 8:54:44 AM
Huh? Are phone numbers tied to physical sims in your country? You can't just ask the phone company to give you a new sim with the same number?by markdown
12/27/2025 at 12:34:22 AM
It was a Google Project Fi phone with a very valuable number (for me, many 8, no 4). Was not able to recover.by Beijinger
12/26/2025 at 9:31:16 AM
If you’re on a contract that can work.If it’s a PAYG sim card then you’re out of luck without the PUK code, which, if you’ve lost the sim then you have most assuredly lost (or never had).
PAYG is a lot more common in parts of western Europe than contracts.
People associate contracts with “overly expensive” phone deals.
by dijit
12/26/2025 at 11:17:10 AM
no, I got my puk code from my phone operator when I moved services before. at least in the UK it works that way.by exe34
12/26/2025 at 11:37:48 AM
Yes, but you are unlikely to have your PUK code (its on the card you got your sim with) if you have also lost the sim.Its a much more losable bit of plastic, and without it (or a contract) why would an operator give you the PUK code for a number they can’t prove you used to have access to? It would be impossible to tell if you are trying to steal someones number.
by dijit
12/26/2025 at 7:02:29 PM
you walk into the shop with your passport or driving licence....by exe34
12/26/2025 at 7:12:09 PM
Try itby dijit
12/26/2025 at 7:21:06 PM
Are you telling me this is a lie: https://www.vodafone.co.uk/help/unlocking-your-phoneby exe34
12/26/2025 at 7:23:09 PM
Please continue up the line to find the context.The grandparent does not have his sim card.
by dijit
12/27/2025 at 1:53:43 AM
> The grandparent does not have his sim card.which is not necessary for transferring your number to a new SIM. when you lose your phone here, you don't lose your number.
by exe34
12/27/2025 at 4:52:10 PM
Depends. Google was not able to recover my Google Project Fi number because I was abroad. And when I was back in the US it was "too late"by Beijinger
12/25/2025 at 11:05:47 PM
> I will never use their services again, I was really digusted by this failureIsn’t this inherent to not choosing an (EDIT: external) account-recovery method?
The flip side to allowing account recovery at Google’s discretion is lessened security for everyone. (Obviously not black and white. And I agree Google should have flexibility for old accounts. But it’s an odd thing to reject a major provider over.)
by JumpCrisscross
12/26/2025 at 1:27:05 AM
You can have all the right details and recovery methods but if at some point they request you to provide the code they sent to the phone you don't have for the last 10 years......... That's it.by subscribed
12/26/2025 at 2:10:13 AM
> if at some point they request you to provide the code they sent to the phone you don't have for the last 10 yearsAFAIK once 2FA is up, you can remove your phone number from GMail.
I know it takes time to set up a recovery account (in case the account is inactive for x months), to remove a phone number, etc. but if one's GMail is important it could be worth doing both now if it hasn't already been done.
by TacticalCoder
12/26/2025 at 1:48:31 PM
Oh, and no, recovery email account is useless. Its been set since the inception and there's not way to use it to regain control over the account.It's a deliberate misnoner.
by subscribed
12/26/2025 at 1:47:30 PM
You will eventually be forced to re-add it at some point.The point is (it's not my account) that unless you religiously update the phone number in all your accounts you will at some point lose access to some of them despite being able to prove with all the other details it's you who created and used them.
Just because.
Because phone number is a very valuable identifier for the ad company.
by subscribed
12/27/2025 at 5:53:35 AM
I don't think you will be forced. I removed it long ago, and still don't have it.by theragra
12/28/2025 at 7:41:02 PM
Go take a look on GrapheneOS discussion forum, there's several people reporting it already.by subscribed
12/27/2025 at 4:42:01 PM
I can't get my Rockstar account because it has 2FA with an app that I somehow lost.by anal_reactor
12/25/2025 at 11:27:40 PM
They did have a method to recover their account that they tried, though - they said that they used the account recovery codes, but that they were rejected. (Those would be the codes that Google gives you when you initially set up 2FA.)by Sophira
12/26/2025 at 1:10:57 AM
When I first got the account, my cell phone was a recovery method. Later in life I imported the cell into google voice... thus when the recovery codes failed, there was no other option.by firefax
12/25/2025 at 11:35:39 PM
Sorry, I meant an external recovery method. Another e-mail address or a phone number.by JumpCrisscross
12/26/2025 at 1:28:00 AM
Another email address is useless.Another phone humber only works if you didn't lose that phone.
by subscribed
12/26/2025 at 6:22:29 AM
Why would another email address be useless?by ashv
12/26/2025 at 7:23:33 AM
I had email address X (gmail) that I hadn't logged into for a long time. One day I tried to log in to it. Correct password, but Google, for some reason, simply decided there's something suspicious about my login and blocked it. X had Y as the "recovery email", and I had access to Y, and I indeed received an email from Google sent to Y that it blocked a suspicious login to X. However, THERE WAS NO WAY TO USE Y TO GAIN ACCESS TO X. Google simply did not offer that option for X, and I had no idea why.by ncann
12/26/2025 at 8:09:47 AM
Google doesn't allow you to recover a Google account using only your recovery email address. Despite its name, the recovery email address is not used to recover Google accounts AFAICT, it's only used to receive notifications about security-related events.by Flimm
12/26/2025 at 1:45:02 PM
This is not a recovery address, it's a lie. Its notifications address, mostly used to force us to draw some parts of our social graph for them.by subscribed
12/25/2025 at 11:23:45 PM
op said they had recovery codes but they didn’t work.by loloquwowndueo
12/26/2025 at 11:50:14 AM
I am fearful of losing my first.last@gmail.com and last.com access presently. Any Google Wallet/Payment folks that might help me..? Please see email in profile if so. Would really appreciate it.Story is I started a new job. I tried to add a corporate address for a corporate card to Google Wallet. This tripped some security indicator requiring me to upload government-issued ID. I did so twice without it working despite first/last/address match. I have tried also submitting an employment verification letter with the corporate address. Haven't heard back on the last attempt.
I have also written but I have low hope that'll work. (Update: Nope, "Billing and Collections" isn't "Payments" but at least they wrote back).
Because of the incomplete verification, all Google service payments are rejected right now. I am presently frantically emptying my Google One storage to get back under the free tier before my paid One subscription runs out. Literally, because I cannot submit a $2 payment I am right now removing attachments from 20 years of correspondence.
This stinks. I just need a human to review what I submitted given the above context. There should be some middle ground between rejecting a new credit card address and de facto locking down someone's entire collection of Google services via manufacturing an inability to pay.
by RhysU
12/26/2025 at 9:08:04 AM
> I will never use their services again, I was really digusted by this failureWas there ever really an agreement that they'd be storing your cherished memories for decades? I still treat email the same way I've done since the 90s. Your email provider is just a cache but you download and backup the messages yourself.
Hopefully this has been a wake up call for you. If you care about data then you need a copy that you control and have a good backup plan.
by globular-toast
12/25/2025 at 10:40:25 PM
Yikes. This post is an unsettling reminder that gmail is a single point of failure in my personal and financial security.by ryukoposting
12/25/2025 at 10:59:57 PM
Email services in general. My worst nightmare is my email provider (which isn't Google) going dark and losing access to everything.by cedws
12/25/2025 at 11:06:29 PM
You can use a custom domain with most providers, so when they go dark you can at least migrate to another one.by saint_yossarian
12/26/2025 at 12:03:55 AM
Two things about fronting with your own domain:1. You have to own that domain forever, until or at least until you're 100% confident that an email intended for you will never be sent to that domain ever again. Even then, there are security risks with giving up the domain.
2. You give up some privacy. You can use mailbox aliases but it doesn't really matter if all the mailboxes are tied to a domain registered to your name and address.
by cedws
12/26/2025 at 1:20:04 AM
1. A little money solves this. You can register for 10 years at a time. Any decent registrar will blow up your email near your domain’s renewal date regardless of renewal status.2. Whois privacy solves this. Free from any decent registrar.
by dangus
12/26/2025 at 12:25:29 AM
Whois privacy is basically standard these days, no?by fragmede
12/26/2025 at 9:55:57 AM
Doesn't completely solve the problem. You now have to pay per (unaffiliated) alias since each requires an independent domain. You also become extremely vulnerable to data breaches because rather than learning that foo@provider is john.doe@provider with IP xxx you instead learn that foo@domain is John Doe, phone number, street address, credit card, etc.This issue goes far beyond email alone. The ICANN domain system effectively rents a string out to you on a temporarily basis and mandates that an Impressum be attached to it. It's a deeply flawed scheme when viewed from the context of both historical hacker culture as well as the fundamental values of a free and open society.
by fc417fc802
12/26/2025 at 4:25:34 AM
Yes but all of your aliases would be under the same domain so one could surmise that the same person uses the domain.by NewJazz
12/26/2025 at 8:35:55 AM
You can usually setup several domains. Some domains are very cheap to register, so you can register some inconspicuous, universal, email provider-sounding domain and add aliases at will.by cromka
12/26/2025 at 6:37:22 AM
For (1) you can prepay i think up to 10 years? And every year you just prepay 1 year again and you will have 10 years to remember that you forgot to pay a domain registration bill.by JackeJR
12/25/2025 at 11:18:51 PM
That is moving the point of failure to the domain registrar. Which is probably less likely, but you are always relying on someone.by 3eb7988a1663
12/25/2025 at 11:35:59 PM
I think that the point here is that your domain registrar will pick up the phone if there is a problem, where Google clearly will not.by dunk010
12/26/2025 at 1:19:34 AM
I use AWS to register the domain and AWS supports up to 8 different MFA factors. I have totp and 4 different passkeys registeredby UltraSane
12/25/2025 at 11:01:49 PM
If you use a password manager like Keepass, you should still be able to log into your other accounts if you lost access and at least with financial institutions you can call, ask that no changes be made with without coming into the branch and showing ID.by firefax
12/26/2025 at 12:06:22 AM
Yes, but many companies will also drag their feet, refuse for "security reasons", or you'll just never be able to reach them in the first place because their only support is an AI concierge that tells you the same thing over and over.As an example Anthropic and OpenAI don't let you change your email address.
by cedws
12/26/2025 at 8:35:39 AM
If you use a password manager like Keepass, you can put your TOTP into it as well. With both a password and a keyfile it's still two factors, technically.by fph
12/26/2025 at 8:40:32 PM
Why don't you keep a copy of your email offline?by ninalanyon
12/25/2025 at 11:38:18 PM
Worst case you need to self hostby tcfhgj
12/25/2025 at 11:40:16 PM
Great when it works. Too many senders will only deliver to widely used hosts, and silently fail for anything outside their tiny allowlist.Note that I'm not even talking about trying to send email FROM a self-hosted account, but trying to get someone else to send email TO such an account.
by Hemospectrum
12/26/2025 at 1:17:33 AM
Realizing this is why I bought my own domain name and pointed the mx records at Gmail. This way I can change it to different mails servers if needed, even self hosted. One useful thing you can do is configure Gmail to forward mail to unknown address to a known one. So I can create addresses like Facebook@ultrasane.com or Amazon@ultrasane.com, etcby UltraSane
12/27/2025 at 4:43:02 PM
My mother only uses the computer for fun. She scrolls Facebook and sends my aunt cringe photos. If she gets locked out of her email, no big deal.Maybe we should just panic less.
by anal_reactor
12/26/2025 at 8:38:38 PM
I'm mystified why technically competent people keep their email in the cloud. Do they never find themselves unable to refer to an email because they are not connected to the web? Isn't obvious that you risk losing everything if the provider goes bankrupt, there is a glitch in their system, or they change the rules?I use Thunderbird on my laptop precisely so that I have a copy of all my email. I can consult it while offline, I can switch providers, change my mail address, without losing anything and without having to rearrange anything.
by ninalanyon
12/26/2025 at 12:35:25 AM
Back up your seeds! Aegis for Android lets you do encrypted exports.by DetectDefect
12/26/2025 at 1:09:00 AM
Or just write down the TOTP seed on paper backups instead of backup codes.by xeonmc
12/26/2025 at 6:07:23 AM
Works for google (should!) but man there are some platforms that don’t expose the Totp code, or let you redisplay it! Sometimes they make you remove the old one before you can make a new one, too.by jonway
12/26/2025 at 7:09:54 AM
So don't put it off until it is too late -- if you haven't already, regenerate and copy TOTP seeds to paper now.When you set up TOTP on a new account, copy the TOTP seed to paper then and there, resist the "I'll do this later".
by cuu508
12/26/2025 at 9:45:13 AM
If it isn't backed up it doesn't exist.Corollary (likely unpopular I'd hazard) - hardware token implementations that I can't back up to paper don't exist as far as I'm concerned.
by fc417fc802
12/26/2025 at 10:43:13 AM
My policy is to enroll multiple WebAuthn keys and treat the second, third etc. key as the backup.by cuu508
12/26/2025 at 3:15:47 PM
I stopped using webauthn for this reason, plus the fact requires a ton of intrusive browser features and access. This surely will enrage most readers, which itself reveals an interesting conditioning that has taken place.by DetectDefect
12/26/2025 at 9:28:27 AM
Few, but screenshot the qr code and print it out.Even Facebook supports totp it's just well hidden.
by jopsen
12/27/2025 at 2:56:21 AM
Print or print to pdf works but feel terrible leaving pdf and printed QR codes around when I have an actual handful of HSM/security dongles in that very same desk drawer :(by jonway
12/26/2025 at 11:44:38 AM
Instagram has them too.by iberator
12/26/2025 at 7:38:15 AM
> seemed like some failure in their systems was causing me to lose access despite having followed proper procedures.I had the same problem with GitHub's backup codes not working: https://news.ycombinator.com/item?id=35735996
by nomilk
12/26/2025 at 6:57:38 AM
Whoa, I noticed something similar. I was updating my password or something a few years back and decided to test the backup codes too. They didn't work. I don't know what went wrong but that got me worried a bit.by kalaksi
12/27/2025 at 10:03:57 AM
Let's be realistic here. The vastly more likely possibility is that you screwed up somewhere with your backup codes.by Ferret7446
12/26/2025 at 9:29:43 AM
Wait a second - if you have gsuite it isn't a regular gmail account. Did you talk to gsuite team? If you even paid there is real support.by rr808
12/26/2025 at 6:29:20 AM
You think that sucks, my childhood angelfire is gone.by iwontberude
12/26/2025 at 7:19:26 AM
Try contacting their support. They did help me regain access to my late 90s angelfire account, even though the original email address I had used was long dead.by cuu508
12/26/2025 at 1:12:49 AM
Save a picture of the TOTP QR code and print it out.by UltraSane
12/26/2025 at 2:05:50 AM
> I will never use their services again, I was really digusted by this failure.Without such measure anyone with your password could "reset" your 2FA.
The solution to "I may lose my 2FA" is not to make GMail a 1FA: it is to configure beforehand your GMail so that if your account is inactive for 6 months, access to your account is given to a person of your choice. It's so that a death spouse (for example) can eventually access the account.
by TacticalCoder
12/26/2025 at 1:08:04 AM
I'm paranoid and print off my TOTP key for each account I make that might matter in any way.by trollbridge
12/26/2025 at 7:23:14 AM
This is exactly what happened to me on Dropbox, where even the backup codes did not work.by iamthejuan
12/26/2025 at 1:11:13 PM
Are you based in the EU? You should be able to file a GDPR request for your data.by remus
12/26/2025 at 1:26:23 AM
[dead]by khana