My main email account had a really simple password.  Something like: "xxabc1234."  Seriously that simple.  Since 2009.  And for three years before that it was "xxabc123." Never any issues, but I figured it was time for a change.  So I decided to change the passwords and recovery options on all five email addresses I have and I discovered something face-palm-worthy:
Gmail's Account recovery options (alternate email or phone number) can be changed once you are logged in without an "authorization code" being sent to the OLD alt-email/phone# accounts to authenticate the change to the NEW alt-email/phone#. If a hacker gets into my account can they simply change the alternate email and phone number to theirs and lock me out?
After your alternate email or phone# are changed you do receive a message to those accounts saying your recovery email or phone were changed and that you can recover your account by clicking a link in the message. But how long will that link work? A day or week? I've gone on two week vacations and did not check any email or phone, would I be locked out permanently? Will I always be able to recover my account using the "original" recovery email/phone# no matter how long ago they were changed? What if recovery email/phone# where changed multiple times will any of those older options work to recover my account or will only the most current recovery accounts work?
Account recovery only seems to be useful if I forgot my password and lock myself out. If a hacker gains access they can lock me out.
Yes I know about 2FA. Password and phone number needed to gain access to my account. I guess I need to replace my "emergency's-only" pre-paid phone.
Is 2FA the only way to secure a Gmail account?
Any alternate web-based email options available that have better/more secure account recovery options?
			
			Gmail's Account recovery options (alternate email or phone number) can be changed once you are logged in without an "authorization code" being sent to the OLD alt-email/phone# accounts to authenticate the change to the NEW alt-email/phone#. If a hacker gets into my account can they simply change the alternate email and phone number to theirs and lock me out?
After your alternate email or phone# are changed you do receive a message to those accounts saying your recovery email or phone were changed and that you can recover your account by clicking a link in the message. But how long will that link work? A day or week? I've gone on two week vacations and did not check any email or phone, would I be locked out permanently? Will I always be able to recover my account using the "original" recovery email/phone# no matter how long ago they were changed? What if recovery email/phone# where changed multiple times will any of those older options work to recover my account or will only the most current recovery accounts work?
Account recovery only seems to be useful if I forgot my password and lock myself out. If a hacker gains access they can lock me out.
Yes I know about 2FA. Password and phone number needed to gain access to my account. I guess I need to replace my "emergency's-only" pre-paid phone.
Is 2FA the only way to secure a Gmail account?
Any alternate web-based email options available that have better/more secure account recovery options?
 
				 
 
		 
 
		