7 ms·
Google has: * Prompts. (Show a notification on a device) * Phone Txt or voice * Backup codes * Authenticator App (ie TOTP) * Security Key: Yubikey and the
by trissylegs 5y ago
Google has:
* Prompts. (Show a notification on a device)
* Phone Txt or voice
* Backup codes
* Authenticator App (ie TOTP)
* Security Key: Yubikey and the like. (You can use some Android phones as a Bluetooth security key)
I'd say google has more options than anyone else right now.
- masklinn 5y agoIirc none of the alternate methods is available until you have given them a phone number. A few months back I finally enabled 2FA on one of my accounts, I wanted to use totp and that option was completely unavailable until I enabled SMS 2FA.
- pilif 5y agoYou can remove the phone number and the other options stay enabled. I removed the phone years ago, because I did not want all of my security for more or less all of my online accounts (password recovery via email) to hinge on the unhelpfulness of a customer service agent of my cell phone provider who is heavily incentivized to be as helpful as possible to any criminal impersonating me
- fsflover 5y agoAnd you of course can trust Google that they actually remove your phone number. /s
- deleted 5y ago[deleted]
- Spivak 5y agoLook, this is silly. Not removing the users number on request is asking for a huge scandal if it ever was leaked or compromised. Pulling this crap isn’t worth it. The value of collecting a few phone numbers from people who don’t want to give it out is nothing.
- masklinn 5y agoYou might not consider it worth it, but some marketroid? Was anyone actually surprised when facebook sent spam texts to 2FA numbers back in 2018? They just floated that balloon and went "whoop sorry bug in the system" and that was that.
- disgruntledphd2 5y agoTo be fair, it was almost certainly a bug in their system. You can argue that they shouldn't have made that mistake, and I'd agree, but stupidity is always more likely than malice.
- masklinn 5y ago> stupidity is always more likely than malice. It's interesting how the supposedly smartest companies of the world are so regularly so stupid in such consistent ways. They're never stupid in a "oh no we deleted all your personal information from our system and now can't track you anymore" way, weirdly.
- disgruntledphd2 5y agothat probably happens, but it doesn't tend to get publicity. More generally, remember that you could be one of those megacorp employees one day, and you might build a 2fa system which logged to a particular place. Later (remember the company is growing for 50% for many years) some new person sees the phone numbers and doesn't realise their provenance (very likely culturally at a place like FB, where things are default open) someone else finds the phone numbers and uses them to send marketing messages. Like, that's what happened (most likely) but it amazes me that people will always want understanding for their own mistakes, but regularly disclaim that others shouldn't have done it, or made a mistake maliciously. To be clear, I have no special insight here, but I think that assuming everything is malice and pre-planned is a less fruitful headspace to inhabit than realising that everyone is human, all companies make mistakes and that's a good prior. To be even clearer, FB should have made this bug impossible (and I'm sure they have now), but given the amount of mistakes I've made I hesitate to cast the first (or indeed one of the last I suppose) stone.