10 ms·
Tell HN: Google requiring phone number to log into Chromebook
Long story short: bought a couple of Chromebooks over the years (as they're nice multi user machines), created Google accounts on each but never gave a phone number. Now after years of use, Google pops up an "unrecognized device" roadblock AFTER I enter the password to log in, with the message "enter a phone number to get a text message with a verification code".
There is no mention of suspicious activity. The only trigger I can think of is a recent modem reset that changed my Public IP, and my new IP doesn't appear to resolve to my old physical location in Google's geoip db.
Am I crazy or does this seem like an extremely cynical attempt to get more phone numbers? I don't even understand how giving them my phone number proves anything as I definitely did not ever give them one previously.
Unfortunately burner phones are not available in my country, so that's not an option.
- berbec 8y agoGoogle voice numbers work, BTW. So since you ha E a Google account, make a burner G voice number and get the text that way.
- LeoPanthera 8y agoYou cannot create a Google Voice number without providing an existing, working, real number.
- berbec 8y agoHuh, I didn't remember that. The last gv number I created was many years ago.
- fredsanford 8y agomailinator has an SMS service
- dchest 8y agoUsing disposable SMS service for what will be used to verify account owner in the future sounds unreasonable.
- RetardedKumars 8y agoif you know about it, everyone does and such services are usually blacklisted
- emerongi 8y agoThey've essentially bricked your machine and are demanding your phone number to un-brick it? Sounds like a case for a legal battle.
- cm2187 8y agoSonos just did the same. They want you to create an account (and therefore give them an email) and otherwise are effectively bricking the device in the latest update. Was time to get rid of this pos.
- greenhatman 8y agoDoesn't Apple do that too? One of the reasons I use Linux on my MacBook.
- toxik 8y agoNo. Why would you spread lies like that?
- henriquemaia 8y agoIt's a question. The user saying that may be wrong in that assumption, but to counter assume intent of spreading a lie is a bit of stretch.
- toxik 8y agoIsn't it true that questions are very handy in rhetorics? No, you do not get a pass just because you claim you were not sure. If you don't know, then don't suggest it. It just muddies the water.
- lloeki 8y agoArguably the sequence of question and affirmation makes it sound very much like the question was purely rhetorical.
- simeonOli 8y agoTwilio SMS is an option at $1 / month
- MrBIGBoom 8y agoInstall Gentoo
- dev_dull 8y agoI removed SMS from my google account for security purposes and use push notifications on the google app. Perhaps you could try that.
- willvarfar 8y agoI have a similar problem with yandex. It's not hardware, just an email account, but I'm locked out of one I used for stuff because they are now asking me for my phone number because of "suspicious activity". I don't want to give them one.
- Springtime 8y agoYup. And Yandex is one of the only free email services left that doesn't require a phone number to register yet they stuck me with a lockout on the account weeks later (still haven't bothered to re-activate the account yet). Not to mention that I created both a custom question and answer with randomly generated strings that couldn't possibly have been known by anyone else, which they confirmed as correct during the lockout and still are demanding a phone number to 'verify'. I mean, really now, how on earth would giving any random phone number further verify I'm the account holder when I already know the correct randomly generated password, secret question and secret answer. Gmail has similarly locked out various accounts with this despite no actual suspicious activity and having a completely unique password. It's a transparent effort by all these companies to gather more user details.
- st1ck 8y agohttps://cock.li/ https://cock.li/ doesn't require phone number (you can also choose other domain name)
- RetardedKumars 8y agoIt's a one man show and can disappear any moment. Following is pure speculation, but it raises concerns as well. Owner of cock.li leaked that he had a job in Romania. What could possibly an US citizen do in Romania? Well, Romania has an US military base, so he could be an IT contractor connected to that, which makes cock.li just a honeypot.
- pas 8y agoProtonMail doesn't require a phone number either for registration.
- zbuf 8y agoI have the same when logging in to my Google account provided by my employer. I don't have 2FA set up, so they have no prior knowledge of my phone number. I'd also like to understand how this is possibly useful? In my case I was travelling, so had no option but to enter the number of the nearest available random person willing to lend me a phone for the purpose, with no idea what it would be used for. It is cynical to suggest it's to boost their network of connected phone numbers, but I can't think of a better explanation?
- hirsin 8y agoWhat you're describing is a "cost proof" - namely that the user has something we can verify that costs some amount of money and is unique. So when the service I work on asks for a phone number verification, it's not always to determine your ID - it's to cut down on spam from users unwilling/unable to set up tens or hundreds of phone numbers, which I imagine is the majority of spammers. Adding it to existing accounts, though, makes less sense to me. Retroactively checking that an active account can cost proof seems like the most intrusive way of doing this, particularly as part of OS login - at this point you have so many signals that you should already be able to detect the user is a spammer or not.
- zbuf 8y agoThen it also seems especially odd to do this on a paid-for G Suite account.
- userbinator 8y agoit's to cut down on spam from users unwilling/unable to set up tens or hundreds of phone numbers, which I imagine is the majority of spammers. If anything I think it's the opposite --- dedicated spammers have shown they can farm resources like accounts of various types, so phone numbers aren't out of their reach. It's the casual users who don't want to give away their phone numbers or setup a throwaway one which will be turned away.
- hirsin 8y ago
- JoshMnem 8y agoStop buying computers that require you to provide your identity to ad companies in order to use them.
- thekashifmalik 8y agoWell said; it really is that simple on principle.
- Tharkun 8y agoWhile this is a good idea in principle, in this case it's a recent development. You can't really go back in time and unbuy it just because Google suddenly decides to be a(n even bigger) dick.
- JoshMnem 8y agoYou could install GNU/Linux on the ones that were already purchased.
- negutron 8y ago> Am I crazy or does this seem like an extremely cynical attempt to get more phone numbers? Nope you are not crazy at all, that's exactly what they are doing. It's the same pattern in practice of online banks that are demanding you give them an SMS capable phone, it's so that they can in the backchannel identify you through AT&T, which is really teh corporate face of the NSA (don't argue with me, 33 thomas st. nyc), and the implications there is that they have many things tied together in fusion centers so they can use something like palantir to instantly profile you when you put in that number and it draws in via their backchannel apis your bank accounts into a single view along with your other information, like medical, civic, etc that's literally what fusion centers do. It's all hooked up for THEIR convenience, and its all keyed off now on google's gaia_id. They tether your phone number(s) to gaia_id and voila all these data sources get drawn in....it's all about the convenience to the five eyes/nato people to force you to use their free sandwich stuff and get everyone tied into the central hub of services that is google So I agree with others: don't use a chromebook. I have an older friend who needed a laptop for work and I made the mistake of getting a chromebook. The f*cking thing didn't do TKIP correctly in WPA2 so it didn't work with my wifi without making major changes to security in a tactical frustration that made ME look like I didn't know what I was doing It was a G d nightmare, but needless to say I will NEVER use a chromebook again, esp after hearing your issue with the phone Just get a refurb lenovo from tigertits or newegg and put linux mint debian edition with xfce on it. The end
- meesterdude 8y agoYou've only been a member for less than 12 hours, but I've already specifically enjoyed your comments in two separate threads. I hope to see more of you in comment threads! You add a lot of value. Whats your "stack"? are you running linux and avoiding google services entirely - or using and mitigating their tracking?
- saryant 8y agoThis conspiracy theory makes no sense. Why on earth would your bank need identify you by phone number when you already have to give them your social security number to open the account?
- Meph504 8y agoGo create a google voice account and put in that number.
- techsupporter 8y agoRequires a "real" phone number to create one.
- newscracker 8y agoI can't offer any advice that can help you quickly or is guaranteed to work. Write a longer and better composed post on some platform, with details of what you've tried, whom you tried to contact at Google, responses (or the lack thereof), etc. Share it on HN, Twitter and elsewhere to get some traction. If you can get it to someone at a senior level, that may help. Sadly, that seems to be the only way to get some companies to pay attention. I'm not sure if your Google account is tied to a Gmail address (it doesn't necessarily have to be), but I would advise anyone who uses (or must use) Google's services to use an email address from another provider so that if you lose access to the Google account, your email also doesn't disappear with it. Further, disentangling oneself from such providers and going with those whose business depends on your monetary support may be a better choice (where feasible). I also get that these suggestions may sound absolutely ridiculous.
- Rebelgecko 8y agoHow do you even find someone to contact at Google? When I tried in the past, the only support was for people that had some sort of recurring SaaS contract or for AdWords
- JAdamMoore 8y agoYou force them to hand over their phone number.
- kaybe 8y agoSome of them read Hacker News.. if your problem makes it to the frontpage you might be in luck. But again, this is really not the way this should work.
- TekMol 8y agoCan you install Linux in these machines?
- Doctor_Fegg 8y agoYes. There’s a Chromebook-optimised distro called GalliumOS. I use it on my HP Chromebook G5 (weighs the same as a MacBook, costs £200) and it works great.
- Fnoord 8y agoChromeOS utilises the Linux kernel itself but without arguing semantics you can install a chroot Linux distribution with Crouton [1]. Whether that supports this specific machine (whatever it may be) I do not know. [1] https://github.com/dnschneid/crouton https://github.com/dnschneid/crouton
- verbify 8y agoYou'd need to get past the login screen to install a chroot, so not appropriate for OPs usecase. Some machines support modifying the bios, but it requires taking off the panels to unscrew the write protect screw.
- djaychela 8y agoYou can install something like GalliumOS depending on compatibility [1], but it's not for someone who's afraid of modification as to make the boot process seamless you need to modify the BIOS. I have an Acer C720 running it, and it works well - it's a light, cheap linux machine that I can take with me wherever and not be too bothered about (because of the replacement cost), but TBH I think installing Linux because of the OP's issue is sledgehammer/nut! Lots of people like ChromeOS (my Mum has a Chromebase, and since she's had it I've needed to provide precisely zero tech support which wasn't the case for either her Mac or the PC she had to replace it), so replacing it with a niche version of Linux may not be the route to go for many. [1] - https://wiki.galliumos.org/Hardware_Compatibility https://wiki.galliumos.org/Hardware_Compatibility
- userbinator 8y agoFor the older ones I've read that you can reflash it to a "normal" PC BIOS and then it becomes a pretty ordinary laptop that will run Linux or Windows or whatever else.
- reacharavindh 8y agoEvil. Imagine those teens at school, that bought Chromebooks because they were more affordable, and now getting pried on like this.. :-( It is this generation that is going to lose the idea of privacy and suffer from these piece of shit corporations. It's almost like watching a movie.
- mavhc 8y agoIf you're a school you're on GSuite for Education so can create as many accounts as you want for free, without phone numbers, and for under 13s
- mverwijs 8y agoParentpost is talking about a different market group. You are talking about chromebooks provided by schools to students. Parent is talking about chromebooks _bought_ by students (because they're cheap and functional).
- mavhc 8y agoFair enough. I'd just pick up a random sim card at any supermarket, comes with a free phone number.
- semi-extrinsic 8y agoFYI being able to just buy a random SIM a any supermarket is not common outsid the UK.
- whyagaindavid 8y agoAre u worried about your country's security services or Google? Not sure of the question. If it is (1) then stop using anything from big 5 tech. It is likely changing ips and locations possibly makes google feel suspicious that your login is being compromised. For my very paranoid friend, I bought 2 X 'U2F' key completely open source at https://u2fzero.com/ https://u2fzero.com/ (unlike some of Yubico keys) . All problems went away. Also remember any form of 2-factor is better than none. Yes, GSM can be hacked and yadayada.. but even one extra factor always slows down. See even a senior Mozilla dev got hacked without 2FA: https://www.theregister.co.uk/2017/08/02/chrome_web_developer_extension_hacked/ https://www.theregister.co.uk/2017/08/02/chrome_web_develope...
- drinkwell 8y agoCan't you just set up an alternative two factor authentication method? How about a Yubikey? I think that maybe if 2FA is not explicitly enabled on the account, Google try and enforce this 2FA 'light' method using SMS
- eikenberry 8y ago+1 ... they pestered me for a phone number until I set up 2FA then they shut up.
- sixstringbudha 8y ago>Am I crazy or does this seem like an extremely cynical attempt to get more phone numbers? Yes it does. The normal Gmail interface I get now has a forgot password link which is by default activated after I enter the username. I have to explicitly jump over that to continue entering the actual password and thus to my mail box.
- tunap 8y agoMy decade+ old Hotmail account, plus two more newer ones, began prompting me for a # "for security" back around 2014. After a couple weeks of "not right now" all three of them locked me out simultaneously. Yahoo still asks for a # to this day(AFAIK... stopped using it after Oauth prompts appeared). Security IS one benefit, but it does not seem to be the most heavily weighted reason. Most don't change phone #s often, if ever. Seems like a super data tracking metric.
- deleted 8y ago[deleted]
- hguhghuff 8y agoI’ve had chrome books as a possible purchase. That’s finished now. I want my machine to be my machine. Google can F off.
- mavhc 8y agoIf you wanted that why would you ever consider a Chromebook in the first place?
- solarengineer 8y agoI am/was considering a Chromebook because of the lower price and the opportunity to run Linux on it
- austhrow743 8y agoIf you were running Linux on it wouldn't this be a non-issue?
- fencepost 8y agoIf that's what you're looking for, buy an off-lease/refurb/used business class notebook that's a few years old. On the ThinkPad side, a T450 or T450s, maybe a T440s if you're going to disable the touch pad, maybe a T430s if you're willing to go back 6-7 years but then you're really going to be looking at likely battery issues and higher weight.
- deleted 8y ago[deleted]
- keypress 8y agoI've had this issue with one email account that I use solely for a very busy email group. Occasionally there is no way at all to log in, as I have no tied phone numbers/email accounts. I think one question was, when did you create this account? Which of course, I have no idea. Anyway that has put me totally off using gmail. I rarely have a phone too, so using a phone number for secondary authentication is a PITA.
- uconucon 8y agoThat's exactly why I don't use Gmail anymore. Tutanota lets you in without a phone number: https://tutanota.com/blog/posts/anonymous-email https://tutanota.com/blog/posts/anonymous-email And there are more, no point in sticking with the big G.
- phobosdeimos 8y agoFunny enough the much maligned evil Win10 allows for the use of a local account. (I am hesitant to give American companies my personal information because they are not beholden to my country's consumer laws).
- EspadaV9 8y agoIt could be that your account was hacked and the hacker has enabled 2FA on your account using their phone number.
- pisky 8y agoHi, op here. They're asking me for any phone number, not for one tied to the account (there is none). I've confirmed this by comparing with the message a friend sees with two factor authentication turned on. Some people are posting here saying they got in using a stranger's number so I still don't understand how providing a number proves who I am.
- fiblye 8y agoI've had this happen with gmail accounts randomly. Most of the time with computers I've been using for years on the same network. The worst occasion I've ever had was the one time I was traveling. I was getting by with only wifi and, naturally, didn't have a phone number to confirm my account with. I didn't have a number bound to my account, either, making the whole process pointless. How did I get into my account? I asked a random guy who walked by if I could login to my email on his phone (since at that point I'd left my wifi area and couldn't login with my own device). It was essential that I check an email at that point, so I didn't have a choice. It was anti-security--I literally gave full access to my email account to some man I never met before in a different country. Google needs to stop pretending it's some security measure. It's not. It's data harvesting, plain and simple. I just wish they'd admit it.
- MawKKe 8y agoEven if you removed that number from you account immediately after logging in, something tells me google will not forget that association. He might not had an account then, but could create one in the future. So now if either of you messes up or does anything even remotely suspicious (in google's eyes) - say goodbye to your account.
- Guest9812398 8y agoI had a Gmail account for a secondary email address that I used at times. One day I logged in with my email and password, and Google said I needed to further verify my identity. Well, my security question was a bogus one because I was confident with my password manager and backups it would not be needed. But, I guess I was wrong, because I didn't anticipate that knowing the password wouldn't be enough for Google. I never got access to the account again.
- mverwijs 8y agoI cannot reproduce this on any of my chromebooks.
- antt 8y agoI can reproduce this on my secondary and tertiary gmails. They require a phone number or security "questions" that I have no idea about. I have effectively lost access to them because of google.
- dazc 8y agoIt proves you are not a bot? The account recovery procedure is usually via a secondary email account or saved backup codes. I know this because I have a friend who's prone to getting himself locked out and I have become his personal tech support guy (not willingly).
- pisky 8y agoI understand the measures they have to go to to stop bots, but Google have more than enough data to know these accounts are not bots (they have years' of browsing history and whatever other hooks they use on Chromeos). Unfortunately these accounts were created years ago and I assumed 'recovery options' would only be required if I forgot my password (which I never would). Beginner's mistake.
- mcny 8y agoThe following is very YMMV. I anal and I'm not a Google employee (would love to be though!). For those in the US, the approach I've taken is to create a Google Voice number. Yes, you need to give it your existing phone number. Then, you can give this number as a backup but the key is to use a two step authentication app like Google authenticator or authy. This is key because like any sane system, two step by SMS has rate limits in place. I don't know the details but it seems like rate limits apply even when an SMS never leaves Google (the SMS originates at Google and ends on your Google voice with no forwarding). Long story short, if you want to fix your problem, try to get two step authentication using an app for your account(s). I think that should do it.
- codedokode 8y agoOutlook Mail does the same. Registered a free email account, logged in from other IP (from the same network) and got a requirement to enter a phone number.
- vezycash 8y agoHad the same experience with an outlook account used for registering sites I don't trust. Microsoft's excuse (lie) was that, my account had sent too many spam messages. Got pissed and abandoned the account.
- newnewpdro 8y agoI'm waiting for the day that LinkedIn will refuse to let me login without configuring a phone number. I don't use smartphones.
- dingaling 8y ago> I don't use smartphones This has nothing to do with smartphones. Last week I decided to create a Youtube account as their premium, ad-free service is now available in the UK. All was going well on my laptop until I hit the page demanding a phone number. Any number, smart or dumb. Not having a burner-SIM to hand I just closed the tab.
- kaybe 8y agoDo these services take landline numbers as well?
- binomialxenon 8y agoMost phone verifications that I've seen do work with a landline. They call you and a text-to-speech bot reads you a code.
- newnewpdro 8y ago> Not having a burner-SIM to hand I just closed the tab. Don't burners get their # recycled? This seems like a pretty awful approach considering most of the sites I see demanding phone #s are doing so under the guise of improved security. It seems likely whoever controls that number will have some authority over the account. All it would take is some stupid notification being sent to the phone number to inform whoever that is of something interesting being possible. Combine that with the fact that burner phones are often utilized by criminals for variety of reasons...
- johnalamosisi 8y agoNot it's a serious attempt to protect your account from hackers
- drasticmeasures 8y agoFormat it and install Linux.
- kartickv 8y agoMaybe giving them your phone number gives Google another signal to catch hackers in another country trying to taking over your Google account. Or a malware server could be prevented from taking over tons of Google accounts? I don't want in abuse, so there are only guesses. I don't mind giving Google my hone number to keep my data secure, and I'm in the majority, so this is a good thing IMO.
- lurker456 8y agoYou should, because anyone that can compromise your phone will be able to get into your email. From there it's a small step to reset passwords (SMS 2FA won't help here, as they also have your phone) to all online services you signed up for with that email.
- kartickv 8y agoYes, but you need to weigh that risk against the risk of not having 2FA. Taking a step back, and responding to the other comment in response to mine as well, I was just speculating. I don't work in abuse, and I'm inclined to trust the Google abuse engineers over myself or random HN commentators to keep my Google account safe.
- hrktb 8y agoTo further lurker456’s point, phone carriers are currently one of the weakest point if you care about security. I assume you are giving your phone number to a lot of entities already (public administration, HR, service prodivers, delivery etc.). From there a simple phone call to your carrier will be enough to reset your contact dmail, SIM and/or have a new one activated.
- RetardedKumars 8y ago> I'm in the majority Judging by your user name you seem to be just another retarded shitskin streetshitter who got a $50 phone before he could get a toilet in his house. Read HN in guest mode rather than posting bullshit like this, kumar-asshole
- atmosx 8y agoI see what you’re saying. As a side note, most likely Google already has your mobile, through a friend who uses an android phone.
- atmosx 8y agoI see a lot of concern around privacy and that’s a blessing. Honest question: Let’s assume for a moment that google wants to do something evil, what kind of info will “providing a mobile number” give to google that the email, searches, possibly DNS queries, oauth2 authentication and browsing tracker will not?
- ken 8y agoPhone number is a universal ID whose transmission and content is managed by another company. It's one which we generally make public, too (that's the point). Plus, unlike email, it's difficult and/or non-free to create more, or manage several of them. A malicious Google with my phone number could easily sell my web searches to the phone company, for example. Or publicly expose my web searches, associated with my phone number (which my friends or employers would recognize). It's basically one less layer of indirection, which means much less plausible deniability. It's not a hard line but there's definitely a gradient they're moving down.
- stephen82 8y agoThey have done this to me a couple of months ago with my Gmail account and got really panicked, because I had all my contacts on it. After I have managed to restore it more than 4 hours later, I permanently deleted my account and Google immediately contacted me with apologies, asking me for the reason I did such thing. They have tried to persuade me to restore my account with a couple of emails, but it was already too late. I cannot trust them anymore. I want to have absolutely nothing to do with Alphabet or Google; if a certain service that I currently use gets acquired by either of them, then I will delete that account too immediately. Enough is enough!
- vageli 8y ago> They have tried to persuade me to restore my account with a couple of emails, but it was already too late. Where are they sending those emails, to your Google account's backup account?
- stephen82 8y agoYes, on my alternative email.
- delbel 8y agoI'm having problems where I am not getting important business emails, but only seeing them on a backup account that gets forwarded all my mail. Also I am getting mail from a guy in India, and he is also getting my email. It's like our accounts got crossed over. As usually, there is nobody at google to reach. How did you get a hold of somebody?
- deleted 8y ago[deleted]
- Elksnis 8y agoWhat's wrong with giving away phone number?
- RetardedKumars 8y agoWhat's right with assuming that one has to use a phone?
- Pica_soO 8y agohttps://www.burnerapp.com/ https://www.burnerapp.com/
- FrozenVoid 8y agoThat is the reason i stopped using Gmail. Random verifications popping up from time to time.
- algog 8y agoUse TextNow app to get temporary mobile numbers.
- ledriveby 8y agoIt might just be a security measure, but tinfoil hats are fun...
- reitanqild 8y agoWhy isn't this on the front page? Seems plenty enough points tjat it should have been there still.
- 013a 8y agoI'd suggest filing a public report to their support on Twitter phrased something like "services inaccessible to underprivileged users", that should trigger enough keywords for their AI managed support to notice. Be sure to get as many quantifiable likes, retweets, upvotes, etc as possible, as that is all data which is used to increase the internal score of the report in their system. Once its been elevated to a human, as rare as that is, play the victim; you're not from the West Coast, so you don't know the West Coast ways, but play the victim, get support behind you, and your issue will be resolved within a week. Good luck!
- auslander 8y agoYes, its new IP adress, they don't like you getting too smart using VPN :) To bypass that, set up MFA using OTP app, like FreeOTP, that should skip 'unknown device' nagging.
- JJMcJ 8y agoMaybe GMail maybe something else, their advice if you didn't have a cell phone was to use someone else's for the initial confirmation code.
- pyman 8y agoCan you imagine if Google gets hacked? Your entire life becomes public. I don’t want to sound paranoid, but it’s a scary thought.
- XalvinX 8y agoif this happens to me i'm fucked. i haven't used a phone in years and use my chromebook for email, my main mode of communication. what do you if you don't have a number?
- S_Bear 8y agoI help people without cell phones set up email accounts (public library). As a result, my cell phone and work phone are blacklisted by Google and unable to receive verification codes. Had to set up my wife's phone as my primary email recovery number. Google's phone number policy is ridiculous.