4 ms·
Funny how "2FA" almost always equates to "phone number". Beware if they claim they don't store your phone number. It's highly likely they store a hash of it fo
by xjay 5y ago
Funny how "2FA" almost always equates to "phone number".
Beware if they claim they don't store your phone number. It's highly likely they store a hash of it for tracking purposes, and proceed to use child-like logic to claim they didn't break any law in doing so.
Furthermore, data brokers use the same hashing algorithm [1] to connect disparate/separate entities, such as your bank, insurance company, fast food chain, etc, basically, any entity you've shared your phone number/email with, in order to gather data on you behind the scenes. How did that happen, you ask? "Out of sight, out of mind."
Google could restrict non-2FA accounts. That way, users could still access their private collection of playlists, but maybe they're no longer able to make comments.
Google and others should offer a standard palette of 2FA options, where the risk factors are left to the users. Let them choose between verified email, some or other TOTP, but try to avoid scavenging private phone numbers, you know, the highest value, globally unique identifier, ooooh.
[1] https://twitter.com/WolfieChristl/status/1288229191759081472 https://twitter.com/WolfieChristl/status/1288229191759081472
- petre 5y agoThey need to store the phone number in order to send an SMS to it.
- nexuist 5y agoIt says in the article that they're using "Google Prompt" which sends a push notification to your phone instead of SMS or TOTP. Regardless I would be surprised if Google's own 2FA didn't support TOTP since....you know...they own probably the most popular mobile TOTP app: Google Authenticator.
- readams 5y agoIn this case if it's not phone number based. It's based on an app prompt on your phone.
- prox 5y agoI like this better, because if you lose your phone/number, it’s a pain to redo all of your phone based 2FA accounts.
- trissylegs 5y agoGoogle has: * Prompts. (Show a notification on a device) * Phone Txt or voice * Backup codes * Authenticator App (ie TOTP) * Security Key: Yubikey and the like. (You can use some Android phones as a Bluetooth security key) I'd say google has more options than anyone else right now.
- masklinn 5y agoIirc none of the alternate methods is available until you have given them a phone number. A few months back I finally enabled 2FA on one of my accounts, I wanted to use totp and that option was completely unavailable until I enabled SMS 2FA.
- pilif 5y agoYou can remove the phone number and the other options stay enabled. I removed the phone years ago, because I did not want all of my security for more or less all of my online accounts (password recovery via email) to hinge on the unhelpfulness of a customer service agent of my cell phone provider who is heavily incentivized to be as helpful as possible to any criminal impersonating me
- fsflover 5y agoAnd you of course can trust Google that they actually remove your phone number. /s
- deleted 5y ago[deleted]
- Spivak 5y agoLook, this is silly. Not removing the users number on request is asking for a huge scandal if it ever was leaked or compromised. Pulling this crap isn’t worth it. The value of collecting a few phone numbers from people who don’t want to give it out is nothing.
- xjay 5y agoTo address the app and phone number concern I have; I doubt it's possible to remain a user of Google services without being forced to give them my phone number at least once, and even if they don't keep it, they'll keep a hash of it to bypass the spirit of the law, and track me across data brokers using a derivative of my phone number instead. My guess is, if they aren't nagging you about verification by phone number, you've likely provided them with your number at least once in the past. On a related note, there's been a push for supporting the Payment Services Directive (PSD2), which requires strong customer authentication (SCA) in most cases, which implies 2FA.
- sneak 5y agoForget 2FA: you can't get a Google Account without giving a phone number during signup.
- Terretta 5y agoYou could as recently as a few months ago (haven’t tried since winter), but you have to be careful from the create account page. If you get asked for a phone number, start over in a new Firefox container. Or, you could do it through YouTube.
- novok 5y agoIt has to be the IP address of something they know the location of with some certainty, near impossible to privately sign up for one. Try it with a VPN or anything from a datacenter IP or any other public place and it's a no go.
- sneak 5y agoI have tried this dozens of times in the last year, with an empty cookie jar. Every time it demands I verify a phone number.
- Fuzzeh 5y agoWhy do they need your phone number? They already have Google Authenticator. (Although authenticator plus is better imo) and they use your email address for that.
- jpalomaki 5y agoMaybe they want to have a backup? People setup 2FA using authenticator, loose phone, no proper backups, backup codes lost. Using access to specific phonenumber as second factor is not too good security wise, but there’s no perfect options. I’d say managing 2FA properly is hard even for IT pros, let alone regular people. Like how many store the backup codes offsite, regularly test backup Ubikeys etc.