9 ms·
This is dangerous. I specifically don't want 2FA on one of my Google accounts because I only have one phone number tied to one device, and this decision by Goog
by ______- 5y ago
This is dangerous. I specifically don't want 2FA on one of my Google accounts because I only have one phone number tied to one device, and this decision by Google to enforce 2FA is going to lock out millions of accounts since some people like to have two Google accounts for compartmentalization reasons (one account for work and another one for play is a common thing to see). So now I need a second phone to get 2FA prompts on the account where I don't want 2FA turned on.
- danuker 5y agoDangerous? For the users maybe. What are they going to do? For Google? They get to clean up (only keep "real" users) and reduce datacenter costs.
- slac 5y agoAnd maybe slow down account creation used for online harassment?
- weird-eye-issue 5y agoA phone number is already needed to create a Google account, completely independently of 2FA and a backup phone number
- Hnrobert42 5y agoLast week I created a gmail account. No phone number was required. I fully expected it to require one, but it didn’t.
- weird-eye-issue 5y agoIt looks like if you create it through the Gmail app that is a workaround to not needing a phone number
- JimDabell 5y agoSMS is not the only – or preferred – 2FA mechanism for Google accounts. You can use any TOTP authenticator application, Google mobile applications like Gmail, physical security keys, or backup codes. Having a single phone number is not a problem for dealing with multiple 2FA-enabled Google accounts.
- hansvm 5y ago> or preferred I just made a new Google account a couple hours ago, and it definitely looks like the preferred mechanism. - There's one stage in the signup flow you can't bypass without SMS (granted, it doesn't automatically save that number to the account if you opt out, so that's nice). - When setting up 2FA you're given giant messaging encouraging you to use a phone number. There's tiny text for other 2FA options. - Those other 2FA options don't actually include TOTP. To enable TOTP you have to enable a "primary" 2FA solution (SMS, hardware key, or push notification), then enable a "secondary" 2FA solution (which can include TOTP), and if you're concerned about the shitty security SMS provides you then need to remove that as a 2FA option. Edit: Mind you, it's probably reasonable given the state of the rest of their ecosystem to not have TOTP as the 2FA for your Google account (like if you have a chicken and egg problem trying to get into an android device with a TOTP app), but TOTP doesn't seem to be anywhere near as preferred as SMS. That, and they do support hardware tokens out of the box (even if the UI doesn't make that super clear), so that's a step in the right direction.
- skynet-9000 5y agoEven though TOTP is provably safer than SMS, it looks like the reason why they want SMS/push as a "primary" is so that they can suck in more phone numbers, since hardware keys have an additional cost that most people won't have. Phone numbers will let them do better ad targeting.
- amk10 5y agoThat is Silicon Valley's reason for 2FA in a nutshell. Phone numbers can only be obtained with identification in many countries. It is a privacy nightmare.
- CarelessExpert 5y agoThen use a TOTP authenticator, which isn't tied to a phone number. As an aside, this is the second comment, now, that is confusing general 2FA with SMS-based 2FA specifically. Given the audience of HN this is honestly surprising to me and makes me wonder how common this confusion is. That alone makes me glad Google is doing this as maybe it'll drive more folks to be educated about 2FA.
- minipoulion 5y agoLast time I checked and tried to have good 2fa on a Google account with only that, TOTP is only allowed as an "additional" means of 2fa and to enable it you already need to have the Google Android promt authentication/phone? 2fa configured (Maybe not exactly like that, but basically you cant just add TOTP without having something worse already added).
- deleted 5y ago[deleted]
- deleted 5y ago[deleted]
- dmoy 5y agoI do not have SMS 2fa on my google account, but I do have TOTP and now U2F. At one point I definitely had only TOTP. At one point, I also had only U2F. What I don't remember is whether or not I had SMS 2fa before and removed it, or never had it at all.
- pilsetnieks 5y agoThey allowed TOTP as primary method for 2FA before they put the Google app prompt in there as an option. So it was possible to set it up that way before 2016-2017-ish, I guess.
- dmoy 5y agookay that would make sense, since I've had 2fa set up for it basically since they allowed it as an option sucks to hear that you can't set it up that way initially anymore, if that's the case.
- skybrian 5y agoI think you're jumping to conclusions. It's unclear what "provided their accounts are appropriately configured" means, but a Google account that's not associated with any phone number or device probably isn't "appropriately configured" and I would guess that nothing will change. But the original blog post was so opaque that I completely misunderstood what they were going to do until pointed out in this article. It's bizarre how badly written some Google blog posts are these days.
- weird-eye-issue 5y agoWhy would you need a second phone? This is one of the more ridiculous things I've read on HN.
- Normal_gaussian 5y agoIt is very common to arrange your life so that you are able to 'hand in' all work devices and walk away. Its a seperation of work and home life that is very healthy, and a reasonable self-protective measure.
- jacquesm 5y agoSuch assumptions are the root of all evil.
- andreareina 5y agoI don't understand what you're saying here. What's wrong with wanting to keep work stuff out of my personal machines?
- jacquesm 5y agoNo, that's perfectly fine. But where it goes wrong is in the assumption that it is 'common'. It isn't common at all to see the opposite either (not everybody wants to carry two phones around, not all phones are dual SIM). The whole work/personal line is blurring more and more and our devices and thought patterns have not kept up with this. You could probably write one of those 'Things programmers assume about online identity' articles by now.
- andreareina 5y agoOh yes work/personal commingling is definitely common in my circles unfortunately.
- CarelessExpert 5y ago
- deleted 5y ago[deleted]
- deleted 5y ago[deleted]
- Jiocus 5y agoYou can use the same phone number for more than one account.
- jdeibele 5y agoIt's possible to set up a Yubikey (or compatible) as the primary 2FA and Google Authenticator (I use Authy but it works the same) as a backup. Once you've done that, you can remove SMS as 2FA. At least you could several years ago when I did it this. I could not remove SMS first, I had to have 3 methods and then I was able to remove it.
- heavyset_go 5y agoThis is intentional. They only want you to have one account.
- dragonwriter 5y agoAFAIK, you can use one phone or key for multiple accounts.