MYTHOSAI

Account security / PRACTICAL GUIDE

Review account sessions and sign out old devices

Identify stale sessions without treating every unfamiliar device label as an attacker.

Before you start

Your own Google account and at least one trusted signed-in device.

Interpret the device list carefully

An account's device page describes recent sessions, not a perfect hardware inventory. One laptop may produce several browser sessions, and a generic device name can be difficult to recognise. Location information can also reflect a mobile carrier, VPN or service routing. An unexpected label deserves investigation; it is not conclusive evidence of compromise by itself.

Start with a trusted device you can keep signed in. If you no longer control any recognised session, use the provider's account-recovery process rather than repeatedly trying random passwords.

Match sessions to real use

  1. Open the genuine account security page and view devices or sessions. Note the most recent activity and the account being inspected.
  2. Compare the list with your current phone, laptop, browser profiles and any recently replaced equipment. Think about travel, remote work and deliberate VPN use before interpreting geography.
  3. Open the details for a device you no longer use. Sign out its listed sessions. If several entries share the same device name, review each rather than assuming one removal covers them all.
  4. Investigate genuinely unexplained activity. Secure the account from your trusted device, review recovery details and connected apps, and remove credentials associated with equipment you have lost.

Verify the sign-out boundary

On an old device you still possess, open the provider's service and attempt a normal refresh. It should require renewed authentication after the provider processes the sign-out. Cached mail or downloaded files can remain on the old device. Remote account sign-out does not erase every local copy.

If the lost device had passkeys or other separate credentials, inspect those account settings too. Removing a browser session and removing a sign-in credential are related but different tasks.

Record useful evidence

For an unexplained session, save the provider's activity details privately, including time and time zone. Do not publish device identifiers or full account screenshots in a forum. If a work account is involved, follow the organisation's reporting process so administrators can check the wider account history.

Build a retirement habit

Before selling, recycling or returning equipment, sign out accounts, remove credentials as appropriate and use the operating system's supported reset process. Verify the next owner sees the setup screen. A tidy device list is helpful, but it does not replace secure handling of the physical device.

Official references

Consult the current vendor documentation if your version or screen differs.

Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.