Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I administer a couple G Suite accounts for small business owner friends purchased direct from Google.

G Suite has incredible phone support. I've called 3-4 times over past 5 years and never waited more than 30 seconds to talk to a knowledgeable and capable tech who resolved the issue immediately. No BS troubleshooting steps, just straight to the heart of the issue.

I recall a couple Irish guys, one Eastern European and one Indian, but none with too-strong to parse accents (these were their locations -- relevant to make the point that Google clearly does have multiple live phone support centers around the world). All fully willing and capable of resolving the issue without passing me around. These weren't incredibly complex issues, but at least a couple were glitches requiring fixes on the backend (vs. mistakes on my part).

Has anyone with a G Suite account and a Cloud account ever tried contacting G Suite Support for the cloud side? Might be worth a try -- they've been helpful for me in one case where the issue wasn't strictly related to G Suite.



G Suite support from Google improved a lot, but for good reasons it is not easy to recover access to an administrator account that was modified to prevent recovery. In a case like this, how support personel can tell a legitimate customer from someone trying to gain access through social engineering?

A local reseller can pay you a visit and verify the situation but hands are tied for the friendly Kumar sitting at a helpdesk facility in India.

Here in Brazil it is even harder, because most customers are unable to communicate well in English and support in Portuguese is not done by native speakers.


> In a case like this, how support personel can tell a legitimate customer from someone trying to gain access through social engineering?

Pretty simple: opt-in KYC. Give people the option to email/fax you their passport or birth certificate or whatever, at any time after they set up their account but before the account is compromised. Extract the relevant ID numbers from the images; then store those numbers, encrypted, the same way you'd store "password recovery" info.

If the account is later compromised on their end, just ask the person attempting to do the recovery to send through the same stuff again, and compare with your recovery fields.

It's essentially the pseudo-biometric, pseudo-"something you have" equivalent of a Secret Question.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: