8 ms·
It's not even about not willing to spend 1$ for a random phone number. Here's a list of things that are wrong with what Google does: - If you want to read you
by vort3 4y ago
It's not even about not willing to spend 1$ for a random phone number.
Here's a list of things that are wrong with what Google does:
- If you want to read your email, you have to use app specific password. I'm ok with that.
- You can't generate app specific passwords if you don't have 2FA enabled. That's some artificial limitation made to force you into adding phone number to your account.
- You can't use authenticator app to enable 2FA. I have no idea why SMS which is the least secure way to send information is a primary method and authenticator app which can be set up by scanning QR from the screen without sending any information at all is «secondary» and can only be used after you give your phone number.
- You can use «notification» to confirm it's you, but you can only do that on the phone. I'm currently logged in in my browser, certainly I could confirm any login attempt from that same browser, wouldn't that be a second factor?
- Nowhere in announcements or help pages or in the Google Account interface they tell you that you can't generate app passwords if you don't have 2FA. The button is just missing and you wouldn't even know it should be there unless you search on the internet.
- Nowhere they tell you the only way to enable 2FA is to link your account to your phone number or to your android/iphone device, the options are just not there.
All of this is just bizarre and ugly. I have no idea why other people are not complaining, probably most of them just accepted that and added phone numbers.
- im3w1l 4y ago> That's some artificial limitation made to force you into adding phone number to your account. Agreed > You can't use authenticator app to enable 2FA. I have no idea why SMS which is the least secure way to send information is a primary method and authenticator app which can be set up by scanning QR from the screen without sending any information at all is «secondary» and can only be used after you give your phone number. The amount of people getting locked out of their account because they lost the phone with the auth app would be unacceptably large, is my guess. Like people lose their phones all the time. Simjackings are rare.
- Szpadel 4y agonot only lost phone, but damaged phone is enough, as you can easily swap sim card but authenticator need to be set up again. BUT there are also one time recovery codes, they could add you option to use those to recover after clicking through few screens of warnings to make sure that you know what consequences does it have
- eternityforest 4y agoThat's one reason I definitely prefer SMS auth to any other method at the moment. What if your phone is damaged while traveling and you are away from where you stored your recovery keys?
- lxgr 4y agoYou can always bring a paper recovery code or FIDO authenticator (both of which are safe against SIM swapping attacks).
- FrenchDevRemote 4y agowe've been told for decades to "not write passwords on postits" and we're really back to square one...
- charcircuit 4y agoideally the paper would be in a safety deposit box / safe and not stuck to your monitor.
- FrenchDevRemote 4y agoIf it fits your need to have it a fixed location, then yes. But he talked about traveling. IDK about you but I don't travel with a safe in my backpack
- lxgr 4y ago
- loosescrews 4y ago> You can't use authenticator app to enable 2FA Are you sure about that? I don't think this is true. I definitely don't have a phone number linked to my Google Account and I have TOTP enabled as well. They even have the Advanced Protection mode which doesn't allow SMS or the authenticator app. Really though, you should do the last thing. Buy some security keys and enable Advanced Protection.
- nagisa 4y agoGoogle used to give more options before. Today if you want to set-up 2FA you must either give them a phone number or use a phone. Only then you can add other authentication methods (this a hardware key) and remove your phone as an option. Source: went through this nonsense a couple years ago and then again a couple months ago with a different account.
- accuratefud 4y agoMan, this thread is such a shinning example of why "trust, but verify" is a phrase. There is ABSOLUTELY an option to enable 2FA on a Google account now that does not require giving them a phone number. There's a clear "Advanced Options" link that lets you choose a security key, which is what folks should be using anyway.
- drsh2k 4y agouse virtual authenticator (https://developer.chrome.com/docs/devtools/webauthn/ https://developer.chrome.com/docs/devtools/webauthn/)
- no_time 4y agoDoes that actually work? I assume google verifies the authenticity keypair(I forgot the specific term) that cannot be extracted authentic devices.
- birksherty 4y agoAlmost nobody in the world have physical key and they shouldn't need to buy one when 2fa apps are sufficient for most people.
- glennpratt 4y agoIt does make sense from one perspective I've seen. Scammers are using 2FA to lock people out of their own accounts and demand a ransom for the tokens. Happened to a friend of mine a couple months ago.
- eternityforest 4y agoI never thought of the whole idea of wanting to hide my number from them, and I suspect most other users haven't either, but it does seem like an issue once you think about it. It might have something to do with not wanting to have tons of spam accounts out there? Do they have code to keep a closer eye on unverified accounts? Or preventing broken devices from locking people out, in a "We must protect users from themselves" kind of way? Google is a mass market company, clearly not a privacy company, anyone who really wants to not be constantly tracked should probably stay away for many more reasons than this.
- throwaway81523 4y ago> It's not even about not willing to spend 1$ for a random phone number. Some sites (e.g. Scaleway.com) won't accept VOIP numbers: they require numbers from actual mobile networks. That is a pain for me since my main phone# is a VOIP number that forwards to my mobile. I do that so I can change my mobile number and just update the forwarding target, or can forward to a landline if I'm someplace with a lousy mobile signal, etc. All of this sucks.
- closetohome 4y agoIt's also not unheard of to enter a valid phone number and get a message that the number has been used too many times and is no longer valid for 2FA.
- nunez 4y agoget an ultra cheap prepaid line then cancel some (like visible) allow you to sign up without providing any of your own PII
- throwaway81523 4y agoThat defeats the purpose, which is to give them a number that works in case they have to contact me. I have a stable VOIP number that forwards to one of various ephemeral numbers at any given time. The VOIP number really is the right one to give them and for them to use. But they are too smart for their own good.
- mid-kid 4y agoThe worst part about this 2FA story is that if you don't have any 2FA methods, Google will effectively lock you out of your account if you're trying to log in from an "unusual" device, i.e. any public (school, library) computer or wireless access point. If you don't have a phone with the proprietary google apps installed and logged into your account, you literally can't login in such situations. Make sure you always have a computer/OS combination that's recognized by google when you travel. I used to constantly get emails about suspicious logins detected simply from moving around hotspots with my phone trying to log into IMAP. This was until I enabled the app password thing, which generated a password that's both shorter and uses less different characters than my old IMAP password.