27 ms·
Google's most ridiculous trick to force users into adding phone number
"To help keep your account secure, starting May 30, 2022, Google will no longer support the use of third-party apps or devices which ask you to sign in to your Google Account using only your username and password."
What does it have to do with phone numbers, you might think? Well, it's not that obvious.
I have beed using FairEmail app to read emails on my phone for many years. Recently, Google made this change, so I thought I need to take some actions to make sure I can continue using my favourite email app. After reading a bit, everything looked pretty simple:
- I could add my email account to my phone and login using google's native authentication methods, or
- «you can use an app password, please see below.»
Sure I don't want to add google's account to my phone just to be able to receive emails via IMAP, so I'll just generate separate app password for my email app, right?
Well, for some reason it's not possible to generate app passwords unless you have 2FA enabled. The option is just not there.
What can be simpler than adding 2FA to my account? I use password managers and my passwords are super strong, but I have no other choice, I'll have to use an authenticator app to continue reading emails on my phone, doesn't make much sense but anyway…
You can't just scan a QR with TOTP secret and enable 2FA for your account. Well, you can, after you enable 2FA by SMS using your phone number, or 2FA by notification on the phone, after you add google account to your phone. But using an authenticator is an «additional method» which is not available until «primary» 2FA method (SMS / phone number) is added. Oh, you can give away your phone number first, enable 2FA, after 2FA is already enabled you can remove 2FA by SMS and keep using authenticator app as your 2FA method, it's simple.
I guess I'll just have to stop using google. Thanks for making my life more difficult and caring about my security, Google.
TL:DR; You can't use «less secure» apps (apps other than official gmail app) to sync emails if you don't want to link your account to your phone number or add google account to your phone.
- 14 4y agoThe only solution I can see is buying a burner phone to avoid these situations. Yesterday tried to set up a new to me used iPhone 7 for my son. It too forces a phone number from you. I had to link my phone number to his phone which I didn’t really want to do.
- vort3 4y agoCan you recommend me any real working website where I could buy cheap one time virtual number that could be used to enable 2FA for my account? And I hope they will never ever again ask me to confirm anything using that number.
- bell-cot 4y agoAh... I sense a very lucrative, low-ethics business model in providing "cheap one-time virtual [phone] numbers" to be used for security-sensitive purposes.
- jqpabc123 4y agoUnfortunately, others have already beat you to it. For example, https://cheapglobalsms.com/ https://cheapglobalsms.com/ I went a slightly different route --- an old spare phone with Ultra Mobile PayGo prepaid SIM. For $3 per month you get 100 minutes of voice, 100 texts and 100 MB data per month. The reason for this is that some security providers throw a little kink in the works by actually making a call to verify your number on sign-up.
- abawany 4y agoI have used voip.ms for years. The basic plan costs approx 1 usd/m with no contracts, etc. and any messages received can be forwarded to and responded from email.
- jqpabc123 4y agoNice try but this won't work with a lot of security providers. Lookup APIs are available to identify line type and most will specifically reject voip numbers. The more obstinate providers I have encountered (some banks for example) will actually have a real human place a call to any number provided at sign up and reject it if they can't verbally talk to you.
- abawany 4y ago
- vort3 4y agoIt's not even about not willing to spend 1$ for a random phone number. Here's a list of things that are wrong with what Google does: - If you want to read your email, you have to use app specific password. I'm ok with that. - You can't generate app specific passwords if you don't have 2FA enabled. That's some artificial limitation made to force you into adding phone number to your account. - You can't use authenticator app to enable 2FA. I have no idea why SMS which is the least secure way to send information is a primary method and authenticator app which can be set up by scanning QR from the screen without sending any information at all is «secondary» and can only be used after you give your phone number. - You can use «notification» to confirm it's you, but you can only do that on the phone. I'm currently logged in in my browser, certainly I could confirm any login attempt from that same browser, wouldn't that be a second factor? - Nowhere in announcements or help pages or in the Google Account interface they tell you that you can't generate app passwords if you don't have 2FA. The button is just missing and you wouldn't even know it should be there unless you search on the internet. - Nowhere they tell you the only way to enable 2FA is to link your account to your phone number or to your android/iphone device, the options are just not there. All of this is just bizarre and ugly. I have no idea why other people are not complaining, probably most of them just accepted that and added phone numbers.
- im3w1l 4y ago> That's some artificial limitation made to force you into adding phone number to your account. Agreed > You can't use authenticator app to enable 2FA. I have no idea why SMS which is the least secure way to send information is a primary method and authenticator app which can be set up by scanning QR from the screen without sending any information at all is «secondary» and can only be used after you give your phone number. The amount of people getting locked out of their account because they lost the phone with the auth app would be unacceptably large, is my guess. Like people lose their phones all the time. Simjackings are rare.
- Szpadel 4y agonot only lost phone, but damaged phone is enough, as you can easily swap sim card but authenticator need to be set up again. BUT there are also one time recovery codes, they could add you option to use those to recover after clicking through few screens of warnings to make sure that you know what consequences does it have
- jqpabc123 4y agoI guess I'll just have to stop using google. Welcome to the club. The fastest way to convince me *not* to use a product is to attach a "Google" label to it. Nothing Google has to offer justifies the drawbacks. NOTE: I do use an Android phone --- but only after it has been thoroughly de-Googled --- starting from a stripped down, bare metal device that won't even power up.
- markdown 4y agoHN needs a bot that posts an inb4 comment every time there's a post about Google or a Google product. These predictable responses don't add any value whatsoever, and they're tiring to read.
- imchillyb 4y agoThe predictable responses, to the predictable responses add even less value than the original comment did. I wish HN would auto-remove these BS comments about BS comments. They're so tiring and boring...
- pessimizer 4y agoYou don't think your comment constantly gets posted as a reply?
- deleted 4y ago[deleted]
- worik 4y agoPot meet kettle....
- Dylan16807 4y agoOnce you're in the pit of bad comments, you might as well try to discourage the original problem.
- deleted 4y ago[deleted]
- superkuh 4y agoGood thing I switched to running my own mailserver in 2013. Now I'm completely independent of google and google accounts. If my @gmail.com email stops working with Thunderbird or other imap clients then that's that. I'm done using gmail. Google hates open protocols. Don't let their claims of OAuth being open fool you. They don't use OAuth, they use OAuth 2 which is the mega-corp version shoved down the IETF's throat where every single corporate implementation is different and not-interchangable. You need a different OAuth2 plugin for every mega-corp.
- vort3 4y agoI have a small free VPS and free domain name (whatever.duckdns.org). Do you think I can make a mail server that works, that could send emails that won't end up in spam folder of other people, and that I could use to create accounts? I have thoughts of running my own mail server, but a lot of sites just won't let you create an account if you don't provide «trusted» email, and by «trusted» most of the time they mean gmail.
- superkuh 4y agoWell, the best time to start is now... but without a domain name I don't think you'll have much luck. If you want to learn how to set up and run a mail server I cannot recommend https://workaround.org/ispmail https://workaround.org/ispmail enough. These tutorials cover all the background and high-level concepts for why you're doing things in addition to the details needed to implement a proper mailserver.
- vort3 4y agoThanks for the link, latest version has some mistakes but in general it's good. I got myself a domain and trying to set up my mail server, but my VPS hosting is blocking outbound port 25. So I can receive emails, but can't send anything. ispmail guide has no workarounds for that…
- walrus01 4y agosmall fee VPS are likely to be in IP space that has a 'bad' reputation from other people who have historically done dumb things in the same /24 or /22, etc, even if it looks clean from RBL checking tools, you have no idea what its reputation is for actual delivery to google and office365.
- more_corn 4y agoOne of the Google cofounders read the book “Nudge” and loved it so hard they invented a process I call “Shove”. You’ll do what we want or we’ll push you into traffic. This is a prime example of using dark patterns to achieve a short term goal at the cost of creating a world none of us want. We must all remain vigilant of this trap both as creators and as users. I applaud you for calling it out. I wish there was something more we could do about it.
- ad404b8a372f2b9 4y agoEvery new feature from Google is a middle finger to their users, then you get some corporate double speak about how it's all well and good and how it makes the product better. Get a Fastmail account, I got one after I got tired of google breaking my IMAP settings every other week. They're cheap, they have most everything you'd need from an email provider, and they don't require a special app like proton.
- snihalani 4y agoI tried fastmail and then there was no search on the drive aspect. had to move back to google
- travisporter 4y agoI'm able to search for filenames in fastmail files. I guess you refer to searching file contents?
- kevin_thibedeau 4y agoYou can mount the files via WebDAV then grep away or point an indexing tool at that as desired.
- throw10920 4y agoFastmail is great at email. If you want a G Suite experience, then you'll need...well, Google.
- vort3 4y agoI think if I'm gonna pay for using email, I'll just try to get any cheap VPS/domain and try to run my own email. It'll be more expensive for sure, but at least it will be my own thing I'm paying for.
- jjulius 4y agoJust depends whether or not the effort it takes to find a VPS company whose IPs aren't blocked by major email providers, and then ensuring that your emails continuously make it through to their destinations, is worth the cost savings. I share your sentiment, but I opted for Fastmail because the effort wasn't worth the savings. YMMV, obviously.
- mxuribe 4y agoSo, at what point will there be a legitimate third option other than Google android phones (and associated ecosystem) and Apple iphones (and associatyed ecosystem)??? And, no, i don't mean rooting a phone, etc. to install Lineage or other alternative operating systems on it. I mean, i want to go out, buy a phone that is decent enough for the basics of what i need to do and is de-googled...not too crazy expensive like an iphone, and comes with legitimate support from a manufacturer. Its exhausting!
- momirlan 4y agonokia 3220
- kevin_thibedeau 4y agoWith any new employer be sure to show up with just a featurephone so you can shoot down any brain dead attempt to force you to link your personal property to corporate authentication.
- mxuribe 4y agoThis is a great idea! :-)
- mxuribe 4y agoI guess i did walk into that one! :-)
- fsflover 4y agoHere you go: https://puri.sm/products/librem-5 https://puri.sm/products/librem-5 and https://pine64.org/pinephone https://pine64.org/pinephone.
- mxuribe 4y agoThanks! I am aware of both, but thought that they were still more for developers, and not ready for prime-time as daily drivers.
- okasaki 4y agoMy biggest complaint is that companies like Google won't make clear policies and instead their messaging is just corposhit nonsense.
- TameAntelope 4y agoI don't see a problem giving Google my phone number.
- _jal 4y agoGoogle can have my phone number when they give me Sundar's.
- TheDong 4y agoFrom your perspective, you're looking at a change that impacted you. From google's perspective, they're looking at a change which reduces phishing and scams by some small percent, and impacts a minuscule fraction of their users. Abuse, scams, phishing, and forgotten passwords are all significant problems which phone numbers help with. I'd be willing to bet these changes end up having an on net positive impact for google's users. How many phishers do you think will be stopped by removing an insecure login flow? How many people do you think want to use insecure apps, but don't have a phone number and refuse to login to their google account on their phone?
- nicce 4y agoPhone number is ultimate crossplatform and cross account identifier, only minority uses burner numbers for this. So I doubt that the phishing is the main driving motivation here, instead it is using phone numbers for easier tracking.
- Nextgrid 4y agoPhone numbers are also the primary thing people keep in contact lists and are very reliable to infer social graphs by stealing people's contacts and connecting the dots server-side.
- xg15 4y ago> How many phishers do you think will be stopped by removing an insecure login flow? How many people do you think want to use insecure apps, but don't have a phone number and refuse to login to their google account on their phone? I actually don't know. Do you have any numbers?
- butz 4y agoDoes using 2FA for GMail login actually add more security? Especially considered that to enable it, first you have to use dubiously secure SMS 2FA.
- 0daystock 4y agoIt's still an additional authentication factor, so in most circumstances, yes it would benefit security. However, you can (and should) use U2F for 2FA, which involves hardware making cryptographic assertions that cannot be phished or man-in-the-middle'd. It's possible to remove SMS as an option after turning this on in Google settings, but unfortunately not so with many other providers.
- walrus01 4y agothe thing about 'adding a phone number' is that hijacking somebody's DID is fairly trivial these days for a good social engineer, you get the customer service department at somebody's cellular carrier to port out the number, or activate it on a new SIM card put into a burner. the SS7/PSTN is horribly broken. SMS based "2FA" is not actual 2FA
- 0daystock 4y agoI think "trivial" is generous. For context, the current market rates for a SIM swap ranges from several thousand USD (T-Mobile) to well over fifty thousand USD (Verizon). It is not really something most people should lose sleep over, in my opinion.
- walrus01 4y agoI classify it as trivial compared to the effort in breaking some real 2FA or otherwise hijacking the start of authority for somebody's online identity/ability to reset their passwords and gain access to an account, like getting possession of a personal domain name to change the authoritative nameservers, set a new MX and receive incoming password-reset emails. Working in the telecom industry I've seen the pressures that first tier phone service reps are under and how they can be socially engineered, if someone is in possession of enough pieces of a person's identity already, to issue a new SIM or port out a number.
- MerelyMortal 4y agoThat seems absurdly high for a SIM Swap. Source?
- 0daystock 4y agoSource: Darknet Diaries, EP 112: Dirty Coms
- drivebycomment 4y ago> TL:DR; You can't use «less secure» apps (apps other than official gmail app) to sync emails if you don't want to link your account to your phone number or add google account to your phone. Not true in multiple ways. "Less secure apps" are ones that don't support OAuth. There are plenty of third party email apps that are not considered "less secure apps". E.g Thunderbird or Outlook, or iOS Mail work perfectly fine, as many others. You can use u2f keys as second factors and don't need to add your phone number as a second factor nor as a recovery phone, as my Google account.
- tpoacher 4y agoI'm not too keen on mandatory 2fa via phone. we need something simpler, like, dunno, some sort of chip on our hands or foreheads perhaps? /s on a serious note, it's annoying how fundamentalists eventually keep getting shit right because of idiots in power fulfilling their prophecies (daniel sloss had a nice comedy skit on this)
- dane-pgp 4y agoThat makes me wonder, how big does the gap have to be between a supposed prophecy and the supposed fulfilment of that prophecy before we can't call it "self-fulfilling" any more? I suppose that on a time scale of thousands of years, a lot of analytical methods break down (and certainly it would be hard to start any new experiments which take that long to complete), but I think that epistemological bonus points should go to anyone whose interpretation of a prophecy guessed the correct ~50 year period for its fulfilment roughly 1800 years in advance. https://en.wikipedia.org/wiki/Millennialism#cite_ref-18 https://en.wikipedia.org/wiki/Millennialism#cite_ref-18
- bsamuels 4y agoEvery tech company is losing the war against credential stuffing. I have a friend working at a series B startup with <10k MAU, you wanna know how many login attempts there are each month? 25,000 login attempts. Per user. That's 250m login attempts each month using stolen credentials. None of the service providers who claim to fix the issue are worth their weight in salt. Shape, Akamai, none of them have a grip on the problem because the attackers are constantly evolving. As you can see, even Google is capitulating despite all the fud that people on HN spread about the company being omniscient. Anyone who thinks this is about advertising/collecting personal data is out of their minds. The worst part is nobody can talk about it because anything you reveal about your problems can give the attackers a massive edge.
- throw10920 4y agoThere are far better ways to stop credential stuffing than requiring a phone number that would be immediately obvious to the people at Google - Hashcash, for instance[1]. 250M login attempts times a few seconds of CPU time is a lot of compute cost to inflict on an attacker who is carrying out the same attack against a bunch of other services at once, and virtually nothing to the few thousands of active users who should only be logging in once every few months each. And yes, a few extra seconds of logon time is viable, because people are used to the login process taking a few seconds and they don't do it very frequently. "Credential stuffing" is straight-up an invalid excuse for asking for someone's phone number. [1] https://en.wikipedia.org/wiki/Hashcash https://en.wikipedia.org/wiki/Hashcash
- bsamuels 4y agoAttackers are using hacked IoT devices to do these attacks. These devices have roughly the same computing power as a mid level smartphone. Attackers do not use their own hardware, and don't care about how much energy is used by their bot devices. In a normal attack, there are maybe 2-3 requests per hour that come from each hacker-owned device. The only thing that hashcat would do is drastically increase power consumption at no cost to the attacker, and turn the application into a battery drainer on mobile devices. So no, Hashcat is not an adequate solution.
- 0daystock 4y agoGoogle is no saint, but there's absolutely no reason to ascribe ill intent to collecting phone numbers of 2FA setup. The reason is simple: Google has billions of users, and at any given time, a lot of them break their devices and lose access to 2FA credentials. Phone numbers, despite all their flaws, are still the most reliable long-term and mostly-immutable attributes which can service as a proxy for identity which can and does aid account recovery at scale. If you crack your phone screen, you can walk to a brick and mortar cell shop, present your ID and get a new phone that receives security codes without a second thought. If you're using Aegis and storing MFA seeds locally, you're on the hook for backups and no one wants that responsibility. Think of it like using social security numbers to authenticate yourself to the bank. Yes, it's terrible, but it's kind of the only thing that works when done on a massive scale. Yes, you can do better at managing your 2FA credentials, but most users cannot - they struggle even having strong passwords. Phone numbers bridge that security-usability gap. To be clear, this isn't an endorsement of the system (I think the user should be allowed to choose), but rather trying to make sense from an engineering perspective.
- throw10920 4y agoThis is an explanation for why Google might ask for phone numbers. This is not an explanation for why Google might require phone numbers. The only valid reasons for the latter are (1) to collect your PII and/or (2) because they think that they know better than you and they're going to force you to do a thing because they think it's in your best interests - in other words, a tyrant ruling over a techno-feudalistic society. If Google was really concerned only for the safety of their users, and not trying to obtain PII for their personal use, they would build an opt-out button, something that would allow users to print out a one-time-use password/encryption key, or register an alternate email address, in lieu of providing a phone number. They don't. Your explanation doesn't hold water.
- cheriot 4y ago> a tyrant ruling over a techno-feudalistic society It's an email app. There are many other options.
- pferde 4y agoI too was hit by this a few months ago, after having to create a Google account for work, and worked around it by running an android emulator where I installed their authenticator app. This was enough to get past the stupid "you have to have a phone" requirement, and gave me access to the TOTP secret, which I then promptly added to my favourite open source 2FA utility. Screw you, Google, you're not getting my phone number.
- rsync 4y agoWhich android emulator do you use ?
- pferde 4y agoI looked around for a least invasive solution, and went with https://www.android-x86.org/ https://www.android-x86.org/ in a small virtual machine.
- ghoward 4y agoWhat's your favorite open source 2FA utility?
- pferde 4y agohttps://www.nongnu.org/oath-toolkit/oathtool.1.html https://www.nongnu.org/oath-toolkit/oathtool.1.html with some very light shell wrapper around it.
- vort3 4y agoI might do this (install an emulator and use auth app there) if I can successfully login from it, I just need a lot of time to do that (internet here is really slow). I asked one of my friends with faster internet to do that for me but google blocked an attempt to login with correct username and password.
- mid-kid 4y agoYou can just scan the QR code instead... The TOTP secret is contained in there, and can be copied into just about any password manager.
- browningstreet 4y agoThey call me about my car’s extended warranty every day whether google has my number or not. I also get a call, every day, precisely at 9:04am, from random numbers matching the first 6 digits of my phone number. Protecting my phone number is a dead effort on my end.
- accuratefud 4y ago
- Nextgrid 4y agoThere's a difference between random spam and having a world-scale stalker knowing your number. The first doesn't have any other details on you, the latter already has plenty and wants the phone number to infer your social graph.
- accuratefud 4y ago
- turdnagel 4y agoJust one thing keeping me on Google for email/calendars: Search. I recently switched back to the Gmail app away from Spark for this. Don't have any examples off the top of my head, but I routinely encountered situations where I'd search for something in Spark or the Apple Mail client and couldn't find it out without using Gmail desktop/app.
- negative_zero 4y agoThank you for posting this. I have had a second email account setup at the company I work for, and hit this exact problem. I thought I was going mad! Especially because I had enabled 2FA with TOTP with an existing company account just a few months ago.
- Melatonic 4y agoCouldn't you just install the Google Profile on any android tablet or spare phone or something, set it up, switch to authenticator (on your normal phone) and then remove the accounts and whatnot from the tablet? Never use SMS at all? The real head scratcher for me here though is that you are fine with Google hosting all of your emails and whatnot but knowing the phone number is a huge problem? If you do not trust Google with your phone number it seems like going with another email service would probably already be a good decision.....
- z9znz 4y agoFor some time now it has been necessary to first setup a phone number as the 2FA solution on a Google account. Only after doing that does it become possible to setup alternative 2FA solutions. So every account I setup, I have to temporarily provide my phone number to enable 2FA, then setup authy, and then delete my phone number. Obviously Google now knows who the real user is, but I haven't been creating additional accounts to be secret. That doesn't excuse the system, but it's not more than a small hassle for me.
- nottorp 4y agoI've given Google my phone number ages ago and I still can't use their smtp to send email from apple's mail.app...
- groffee 4y agoA lot of 2FA is security theater and doesn't provide any actual protection. If your phone gets taken by the police (or stolen), with an authenticator app or sms they can get into your account easily but you're locked out. A hardware key is the way to go but even then there's no guarantee the police wouldn't take that as well, and most people think having an app on their phone is enough. And 'email alerts' are even worse, if someone has taken your computer and has complete access to your accounts, an email saying "is this you?" is just gonna make them laugh.
- Nextgrid 4y agoTo be fair the threat model for most people isn't the police or any other physical attack - instead it's remote attacks such as phishing, malware, etc.
- dudus 4y agoI think the fact you can't generate an app password without a 2FA is because it never made sense. You would be better off just logging into your account directly. Now that you can't do that it makes sense. I'd file that as a FR. One point is that app passwords can be a security issue in itself. If you have one the security page on Google alerts you with a big flashy yellow exclamation point and recommend you you to remove it. I did it, broke my email and took a few days to connect the dots, recreate a new app password and setup email again. I think the problem they have is that mail clients don't do oAuth. So you always have that security weak link if you need IMAP/pop access.
- MilaM 4y agoHere is how I solved the same problem a couple of weeks ago. If you still have an active session in a browser, you can add a recovery e-mail address to you account security settings. After that I was able to add a Yubikey as a second factor without adding a phone number. This should also work if you want to use TOTP as a 2F instead of a Yubikey.
- vort3 4y agoI might try this, thanks. Yes, I do have session in my browser and I would use it as a second factor to manually approve every login to my account from my browser if I had option to do that, but Google doesn't allow that. You can only confirm logins from android or apple device.
- MilaM 4y agoIt worked for me and I did not have to give Google my phone number to "unlock" the other 2FA options and subsequently app passwords. I used the Yubikey, but I think it should work if you only use TOTP.
- vort3 4y agoI added reserve email and in 2FA setup dialog there's still no authenticator option, just Yubikey, notification on Adnroid, or SMS by phone number.
- nprateem 4y agoShame HN is 80% tropes now from paranoid introverts who don't want to go back to the office and who could write Dropbox in half an hour
- pb7 4y agoIt's painfully obvious that a non trivial number of users here maintain little contact to ordinary people who make up 99% of the user base.
- weq 4y agoWhats painfully obvious is how people and profit and interchanged so seemlessly by the vultures who pray on the "ordinary people" and how desensitised we have become as a collective to the notion. What HN shows is that a non-trivial amount of peoples entire life is focused on exploiting others inadequacies and this exploitation is portrayed as "normal" by those who profit and abormal by those who now see how invasive ad companies become. Letting your child sit through an ad is akin to child abuse in my head. Like taking them to a church.
- jqpabc123 4y agoMost of the user base are "sheeple" who subscribe to whichever corporate marketing program has the largest budget. Google itself is a major player in this game. "You laugh because I'm different. I laugh because you're *normal." *normal - Average, ordinary, unremarkable, the same
- pb7 4y agoUsing "sheeple" unironically says more about you than it does about them. There's nothing remarkable about being too socially stunted to be able to acknowledge groups beyond your own.
- jqpabc123 4y agoI fully acknowledged groups beyond my own --- and the fact that corporations acknowledge and abuse these groups vulnerability to social pressure. After all, this is what advertising (i.e. Google) is all about --- coercing people to act a certain way and buy certain things in order to fit into a particular social stereotype. Which is worse --- being socially stunted or socially vulnerable?
- sir 4y agoIf all you need is IMAP/SMTP you can use this local proxy to continue using the “less secure” app without needing app passwords: https://github.com/simonrob/email-oauth2-proxy https://github.com/simonrob/email-oauth2-proxy
- vort3 4y agoThat looks like a really great option for me, thanks a lot for the link.
- ASalazarMX 4y agoThe Fair Email FAQ [1] states that it supports Google's OAuth, so why don't you authenticate with that? "OAuth for Gmail is supported via the quick setup wizard. The Android account manager will be used to fetch and refresh OAuth tokens for selected on-device accounts. OAuth for non on-device accounts is not supported because Google requires a yearly security audit ($15,000 to $75,000) for this. You can read more about this here [2]." 1. https://github.com/M66B/FairEmail/blob/master/FAQ.md#user-content-faq111 https://github.com/M66B/FairEmail/blob/master/FAQ.md#user-co... 2. https://www.theregister.com/2019/02/11/google_gmail_developer https://www.theregister.com/2019/02/11/google_gmail_develope... So it maybe works, or maybe not, because they're not paying Google for the security audit.
- vort3 4y agoBecause I'm using a fork that is not signed by Google and it can't use OAuth, unfortunately.
- adhesive_wombat 4y agoI also really hate the use of Telegram by ostensibly open source projects for this reason.
- cookiengineer 4y agoNote that this is why gmail is unreliable in terms of opsec now. Recovery SMS or phone number implies out of control of users. One day the CEO gets SIM swapped over night...until that day nothing will change.
- bgdkbtv 4y ago[flagged]
- AnonC 4y agoI have a tangential story on how providing a phone number isn’t going to help either. I have an important Gmail account where I recently had to change the password (because the only password set several years ago didn’t work). Since it was important, I didn’t want to risk the account becoming inaccessible and hence provided my phone number as the recovery number. After changing the password through a browser, the iOS Mail app complained that the password for this account is invalid and that I should enter it. So I go there and flow through the Google login pages (since this is setup as a Google account), and then it repeatedly tells me that it’s incorrect and that I should recover my account. Visiting the recover account page tells me that it cannot help me at this moment! I’m furious at how stupid Gmail (and the people in Google writing this application) can be. I haven’t accessed that account over the last few days and am hoping I can get back in after the Google bots have cooled down. I have no idea what I can do if that account becomes permanently inaccessible because some “machine learning” algorithm messed things up. :( I’ve decided to close my Gmail accounts (these were old ones) if I can manage to download the data from those.
- drsh2k 4y agoI was able to get around SMS 2FA by adding a virtual security key then turning on TOTP (https://developer.chrome.com/docs/devtools/webauthn/ https://developer.chrome.com/docs/devtools/webauthn/)
- rdschouw 4y agoI just gone through this process myself. You can add another 2FA method later and THEN delete your phone number. That's what I did.
- gbasin 4y agoIs this to protect them from being a vector for span? Making it costly to create new usable Google accounts
- MetroWind 4y agoIt can't be helped I think. The chain of trust must start somewhere. What if someone secretly have your password and enable 2FA? The addition of the 2nd factor of auth is a big deal and the process should be as secure as possible.