Live data from Hacker News

Google's most ridiculous trick to force users into adding phone number

news.ycombinator.com

101–110 of 250 posts

Re: Google's most ridiculous trick to force users into adding phone number

#101
post #10
post #8

Good thing I switched to running my own mailserver in 2013. Now I'm completely independent of google and google accounts. If my @gmail.com email stops working with Thunderbird or other imap clients then that's that. I'm done using gmail. Google hates open protocols. Don't let their claims of OAuth being open fool you. They don't use OAuth, they use OAuth 2 which is the mega-corp version shoved down the IETF's throat…

I have a small free VPS and free domain name (whatever.duckdns.org). Do you think I can make a mail server that works, that could send emails that won't end up in spam folder of other people, and that I could use to create accounts? I have thoughts of running my own mail server, but a lot of sites just won't let you create an account if you don't provide «trusted» email, and by «trusted» most of the time they mean gm…

small fee VPS are likely to be in IP space that has a 'bad' reputation from other people who have historically done dumb things in the same /24 or /22, etc, even if it looks clean from RBL checking tools, you have no idea what its reputation is for actual delivery to google and office365.

Re: Google's most ridiculous trick to force users into adding phone number

#102
post #55

I too was hit by this a few months ago, after having to create a Google account for work, and worked around it by running an android emulator where I installed their authenticator app. This was enough to get past the stupid "you have to have a phone" requirement, and gave me access to the TOTP secret, which I then promptly added to my favourite open source 2FA utility. Screw you, Google, you're not getting my phone n…

What's your favorite open source 2FA utility?

Re: Google's most ridiculous trick to force users into adding phone number

#103
A lot of 2FA is security theater and doesn't provide any actual protection.

If your phone gets taken by the police (or stolen), with an authenticator app or sms they can get into your account easily but you're locked out.

A hardware key is the way to go but even then there's no guarantee the police wouldn't take that as well, and most people think having an app on their phone is enough.

And 'email alerts' are even worse, if someone has taken your computer and has complete access to your accounts, an email saying "is this you?" is just gonna make them laugh.

Re: Google's most ridiculous trick to force users into adding phone number

#104
post #2

The only solution I can see is buying a burner phone to avoid these situations. Yesterday tried to set up a new to me used iPhone 7 for my son. It too forces a phone number from you. I had to link my phone number to his phone which I didn’t really want to do.

A "2FA Mule" is a special kind of burner phone that forwards the authentication to the endpoint of your choice - in my case, email:

https://news.ycombinator.com/item?id=29710908

Re: Google's most ridiculous trick to force users into adding phone number

#105

Every tech company is losing the war against credential stuffing. I have a friend working at a series B startup with None of the service providers who claim to fix the issue are worth their weight in salt. Shape, Akamai, none of them have a grip on the problem because the attackers are constantly evolving. As you can see, even Google is capitulating despite all the fud that people on HN spread about the company being…

at 25,000 login attempts per user if you're not doing common sense rate-limiting of attempts per username, and rate limiting per IP space origin (either discrete ipv4 /32 or attempts from within a whole ASN), you've got other problems. the rate-limit and blockage time for attempts should increase ban time/lockout-timer on an exponential time scale the more that a single browser/useragent/browser fingerprint/IP makes…

>yes obviously there are people out there with fully automated systems who will try massive lists of commonly used plaintext passwords for authentication if you don't throttle/rate-limit it.

and those people use single browser/single useragent/single browser fingerprint/single IP

the people competent enough to send millions of requests are usually also competent to send hard to detect requests

there are dozens of (free)tools/services offering those capabilities for LEGITIMATE purposes(like scraping)

there is an even bigger underworld market for paid tools for illegitimate purposes

Re: Google's most ridiculous trick to force users into adding phone number

#106
post #92

Every tech company is losing the war against credential stuffing. I have a friend working at a series B startup with None of the service providers who claim to fix the issue are worth their weight in salt. Shape, Akamai, none of them have a grip on the problem because the attackers are constantly evolving. As you can see, even Google is capitulating despite all the fud that people on HN spread about the company being…

> Anyone who thinks this is about advertising/collecting personal data is out of their minds. Sorry, but that trust has been burned and I don't see a path to recovery. Support hardware tokens or get off my lawn. https://www.eff.org/deeplinks/2019/10/twitter-uninentionally... https://techcrunch.com/2018/09/27/yes-facebook-is-using-your...

Pretty sure they do support hardware tokens.

Re: Google's most ridiculous trick to force users into adding phone number

#107
post #92

Every tech company is losing the war against credential stuffing. I have a friend working at a series B startup with None of the service providers who claim to fix the issue are worth their weight in salt. Shape, Akamai, none of them have a grip on the problem because the attackers are constantly evolving. As you can see, even Google is capitulating despite all the fud that people on HN spread about the company being…

> Anyone who thinks this is about advertising/collecting personal data is out of their minds. Sorry, but that trust has been burned and I don't see a path to recovery. Support hardware tokens or get off my lawn. https://www.eff.org/deeplinks/2019/10/twitter-uninentionally... https://techcrunch.com/2018/09/27/yes-facebook-is-using-your...

the average person don't have any idea what's a hardware token. google is not catering to HN readers, they're catering to your grandma, your parents, your little brother/sister, your tech illiterate neighbor.

They couldn't care less about the habits of a nerd on archlinux with ublock, noscript, firefork a vpn, hardware tokens and 2FA everywhere with recovery code split in 7 different location.

Re: Google's most ridiculous trick to force users into adding phone number

#108

Google is no saint, but there's absolutely no reason to ascribe ill intent to collecting phone numbers of 2FA setup. The reason is simple: Google has billions of users, and at any given time, a lot of them break their devices and lose access to 2FA credentials. Phone numbers, despite all their flaws, are still the most reliable long-term and mostly-immutable attributes which can service as a proxy for identity which…

Google asks for a phone number in this context even for accounts which are integrated with an external identity provider and for which Google does not need to (or rather: must not) provide a recovery option. Furthermore, in most countries, phone numbers (especially mobile phone numbers, as suggested by Google) are very susceptible to targeted attacks, so I hope that Google does not use them as a recovery option even for non-corporate accounts.

I think it's some sort of state machine glitch that this account feature only becomes available after adding a phone number. I couldn't come up with any other explanation. And I really hope that the static passwords stay indefinitely because the XOAUTH extension for IMAP is brittle, hostile to open-source software because of the API key requirement, and does not add security anyway. (I wouldn't mind manually rotating the passwords once per quarter, though.)

Re: Google's most ridiculous trick to force users into adding phone number

#109
post #84

Earlier quoted context omitted.

You can always bring a paper recovery code or FIDO authenticator (both of which are safe against SIM swapping attacks).

we've been told for decades to "not write passwords on postits" and we're really back to square one...

ideally the paper would be in a safety deposit box / safe and not stuck to your monitor.

Re: Google's most ridiculous trick to force users into adding phone number

#110
post #92

Earlier quoted context omitted.

> Anyone who thinks this is about advertising/collecting personal data is out of their minds. Sorry, but that trust has been burned and I don't see a path to recovery. Support hardware tokens or get off my lawn. https://www.eff.org/deeplinks/2019/10/twitter-uninentionally... https://techcrunch.com/2018/09/27/yes-facebook-is-using-your...

Pretty sure they do support hardware tokens.

+1..get a yubikey or similar device, problem solved.
Post reply on HN