4 ms·
Microsoft "consumer" (live.com, etc) accounts are like this. They have a whole set of advanced, secure options like security keys, TOTP, etc but they force you
by pch00 3y ago
Microsoft "consumer" (live.com, etc) accounts are like this. They have a whole set of advanced, secure options like security keys, TOTP, etc but they force you to have either an email or SMS recovery option configured :(
Google on the other hand, do this correctly. You can configure a consumer Google account to only have secure options listed.
- probably_wrong 3y ago> Google on the other hand, do this correctly. You can configure a consumer Google account to only have secure options listed. Are you sure about that? I couldn't activate 2FA in my Google account for years because they didn't enable the option without giving a phone number first. Based on my HN experience, many users gave their phone number from the get go and therefore didn't notice that they couldn't activate 2FA without it.
- pch00 3y ago> Are you sure about that? I couldn't activate 2FA in my Google account for years because they didn't enable the option without giving a phone number first. Just checked, and yes, no phone or email recovery methods configured.
- eep_social 3y agoThe trick with a newly created google account (assuming the regular account creation flow) is to give a phone number at signup and then remove it. There are some non-standard account creation workflows that used to work without a phone number at all but I haven’t tired recently and iirc the last time I did it didn’t take long for google to require me to “verify” my humanity with a phone number.
- sdflhasjd 3y agoThey're even worse because, last time I checked, they are effectively a single factor as you could use them for resets.