4 ms·
There are other companies like Google that first require you to set it up over SMS before they allow you to add a security token.
by kroeckx 9y ago
There are other companies like Google that first require you to set it up over SMS before they allow you to add a security token.
- tptacek 9y agoThis is unfortunate. They presumably do it because people routinely lose 2FA keys, but rarely lose their phone number, and so requiring an SMS backup first cuts down support requests. What it means in practice is that when we train people to set up 2FA, we have to teach them a somewhat elaborate dance of enrolling their phone number, adding the U2F and TOTP authenticators, removing their phone number, and then making sure they don't have a recovery phone number set.
- desdiv 9y agoThey do that to prevent account farming. Google is one of the very few companies that refuses to accept my VoIP DID number for 2FA, because they know it's not a "real" number. A wise move, considering that SMS-capable DID numbers only cost a few dimes when you buy in bulk. They're not insisting on 2FA-by-SMS since you can immediately disable it after you prove that you own a valid phone number and thus is much less likely to be a spammer.