July 16, 2021

"Bad Authentication" error- what you can do

I need a little bit of help on this one.

I’m still not entirely sure what Google is up to. It is clear that they are working on shutting out everything that isn’t genuine Android, but I can’t tell if they are just doing an A/B test on new bot detection code or if they are already doing a slow roll out. Either way, I am not affected (yet) and as long as I’m not personally hit by it, debugging this is a very slow and painful process, involving lengthy email discussions with users who can’t log in, but also lack the required skills to diagnose the problem. To put it in an allegory, it’s like playing correspondence chess someone, who doesn’t know the rules of the game.

Things that don't help Please do not send an email just to tell me that you can't log in, hoping that I'm going to personally teach you some secret handshake for bypassing the problem. You will be disappointed. I maintain this blog in order to not do this, so if you don't find an answer here, it means, there is none.

Currently, there are two things that can help with getting this fixed:

  1. If you know how to use Wireshark and can log in from an Android phone, I’d be interested in a) a dump of the SSL handshake and b) the sdk version of the device.
  2. If you happen to have a Linux box, I can SSH into and observe the problem on myself (this means, I also need access to the account in question), that would definitely speed things up.