3 ms·
A lot of people commenting on using 2FA options other than SMS, but to the best of my knowledge it will only work after you’ve already associated a phone number
by hrktb 5y ago
A lot of people commenting on using 2FA options other than SMS, but to the best of my knowledge it will only work after you’ve already associated a phone number to the account.
Wanted to check if I’m just dumb, and all recent answer point to the same issue:
https://www.quora.com/Is-it-possible-to-use-Google-2-step-verification-without-a-mobile-phone-number https://www.quora.com/Is-it-possible-to-use-Google-2-step-ve...
- CarelessExpert 5y agoMy Google account is configured right now to only support the Android prompt, TOTP, and Backup Codes. SMS is specifically not enabled, both for 2FA and account recovery. Either that answer is out of date or it's lacking nuance. I haven't done it in a while, but it may be that you need SMS 2FA initially, and then once you've added TOTP you can then remove SMS. But SMS is absolutely not required and anyone who thinks it is and is avoiding 2FA for that reason needs to go take a second look at their security settings.
- hrktb 5y agoI can also remove SMS as 2FA on my account, but I’ve had to give a phone number on all my accounts at different points in time, and they got confirmed by SMS. What I was pointing at is not that SMS is the only option but that the phone number + confirmation seems mandatory at least once.
- deleted 5y ago[deleted]
- prirun 5y agoIMO, the bottom line is that Google wants your phone number, I'm guessing so they can somehow further target ads. They bugged the hell out of me a while back trying to get a phone number, even though I had a backup email address configured. They haven't bugged me for a while now, but that's likely because now they're going to try to force me to give them a phone number.
- fragileone 5y agoThing is you can delete it immediately after you've set up your account with alternate 2FA eg TOTP/authenticator.
- prirun 5y agoDo you believe they actually delete it? I don't. I deleted my account with Digital Ocean years ago, because I use NoScript and every time I went to a new page at DO, it required me to enable more 3rd-party domains. I switched to Vultr.com because they only use their domain for their web pages. Recently I received an email from DO that my acct information may have been accessed by some hack. I replied to that email, requesting that they delete everything on their systems relating to me. They said I had to sign in and purge my account. I already did this, when I switched to Vultr.com. But I tried anyway. It wouldn't let me sign in (Duh! I already deleted the account), so won't let me purge my info. When I explained that DO would have to delete it, they never replied. They obviously still have my info or they couldn't have emailed me. My level of trust that a company has actually deleted everything they say they are deleting is about zero. If it's to their advantage to keep it, they will.
- CarelessExpert 5y ago> They haven't bugged me for a while now, but that's likely because now they're going to try to force me to give them a phone number. This and your other reply in this part of the conversation are purely paranoid speculation. Frankly, if you're this concerned about Google's nefarious intent, you should get off their platform. They probably already know a lot more about you than just some random phone number.