Unfortunately even doing everything right is no guarantee. I have Google accounts that Google will not let me into even though I have the correct password because it requires a connection from the same network as past logins, which are in places I no longer live. I've read accounts from others in the identical situation.
My answer to this is that I've completely moved off of Google except for an account I use for YouTube/Maps access that I could painlessly lose.
> I have Google accounts that Google will not let me into even though I have the correct password because it requires a connection from the same network as past logins
I don't get how that can possibly be a requirement. I mean, it's trivial to dream up a scenario where it is 100% legit to be in this situation.
I loathe these kinds of security measures that make up literally impossible tasks for some people.
There should always be a break-glass. That break-glass should not be tied to a piece of hardware. That's why I don't use 2FA unless there are break-glass OTP, or I can use a generic authenticator. Authy, for example, allows me to install 2FA on my phones and desktop - no need to worry about losing my phone meaning I can't get into my accounts.
My bank on the other hand, uses Symantec VIP, which has no backup or break-glass. So my bank (the only one offering 2FA) is 1FA.
Most OTP systems will show you a bunch of recovery codes you can write down or print out or email yourself or whatever you want to do with them.
Authy is a great option but annoyingly it's tied to your phone number rather than a username, so you can lose access to that if you break your phone in a place where you can't easily get a new SIM card (i.e. if you're on holiday). You also need to remember to actually enable multi device in the settings, as it's off by default. It's a good service, but it's not without its own pitfalls.
I'm always wary of custom 2FA systems that banks and governments like to use, especially if they do nothing to actually avoid phishing. If you're going to make your own version of TOTP, at least solve the biggest problems TOTP faces. For this reason I like to configure krypt.co as my primary 2FA method (for as long as that's kept running) with TOTP (and optionally device-local webauthn) as a backup solution.
Same, correct password but because God forbid I'm a human and I moved my body to a different network you don't get access.
All these algorithms and engineers yet login functionality fails.
There must be something else in your inability to access your account because I have been using a VPN for more than nine (9) years, changing locations every 5-7 days, and I have no problems accessing my Google account.
Interestingly, I remember creating a new Google account a couple of years ago from the Philippines, without a VPN, and when I moved back to the US I couldn’t access it anymore.
I believe the account’s age has something to do with the restrictions.
My answer to this is that I've completely moved off of Google except for an account I use for YouTube/Maps access that I could painlessly lose.