Earlier quoted context omitted.
> Anyone who thinks this is about advertising/collecting personal data is out of their minds. Sorry, but that trust has been burned and I don't see a path to recovery. Support hardware tokens or get off my lawn. https://www.eff.org/deeplinks/2019/10/twitter-uninentionally... https://techcrunch.com/2018/09/27/yes-facebook-is-using-your...
Pretty sure they do support hardware tokens.
Google's most ridiculous trick to force users into adding phone number
111–120 of 250 posts
Re: Google's most ridiculous trick to force users into adding phone number
#112I guess I'll just have to stop using google. Welcome to the club. The fastest way to convince me *not* to use a product is to attach a "Google" label to it. Nothing Google has to offer justifies the drawbacks. NOTE: I do use an Android phone --- but only after it has been thoroughly de-Googled --- starting from a stripped down, bare metal device that won't even power up.
I bought Pixel phones for my wife and I because the price and ease of use to save my kids pictures was absolutely worth it. I haven't found a service that functions as well as Google Photos. She takes pics and I take pics, and we have a shared account that backs it all up without any messing about. I have done precisely ZERO tech support for my wife since buying this service and phones and I will probably never leave…
I myself tried to power off the device. Holding the lock button actually didn't show a power off menu, it opened Google assistant. As far as I can tell the only way to turn off the phone was to say "Turn off" to the assistant.
Re: Google's most ridiculous trick to force users into adding phone number
#113Earlier quoted context omitted.
This is an explanation for why Google might ask for phone numbers. This is not an explanation for why Google might require phone numbers. The only valid reasons for the latter are (1) to collect your PII and/or (2) because they think that they know better than you and they're going to force you to do a thing because they think it's in your best interests - in other words, a tyrant ruling over a techno-feudalistic soc…
> a tyrant ruling over a techno-feudalistic society It's an email app. There are many other options.
Re: Google's most ridiculous trick to force users into adding phone number
#114A lot of 2FA is security theater and doesn't provide any actual protection. If your phone gets taken by the police (or stolen), with an authenticator app or sms they can get into your account easily but you're locked out. A hardware key is the way to go but even then there's no guarantee the police wouldn't take that as well, and most people think having an app on their phone is enough. And 'email alerts' are even wo…
Re: Google's most ridiculous trick to force users into adding phone number
#115One point is that app passwords can be a security issue in itself. If you have one the security page on Google alerts you with a big flashy yellow exclamation point and recommend you you to remove it. I did it, broke my email and took a few days to connect the dots, recreate a new app password and setup email again.
I think the problem they have is that mail clients don't do oAuth. So you always have that security weak link if you need IMAP/pop access.
Re: Google's most ridiculous trick to force users into adding phone number
#116Earlier quoted context omitted.
we've been told for decades to "not write passwords on postits" and we're really back to square one...
ideally the paper would be in a safety deposit box / safe and not stuck to your monitor.
But he talked about traveling.
IDK about you but I don't travel with a safe in my backpack
Re: Google's most ridiculous trick to force users into adding phone number
#117Every tech company is losing the war against credential stuffing. I have a friend working at a series B startup with None of the service providers who claim to fix the issue are worth their weight in salt. Shape, Akamai, none of them have a grip on the problem because the attackers are constantly evolving. As you can see, even Google is capitulating despite all the fud that people on HN spread about the company being…
There are far better ways to stop credential stuffing than requiring a phone number that would be immediately obvious to the people at Google - Hashcash, for instance[1]. 250M login attempts times a few seconds of CPU time is a lot of compute cost to inflict on an attacker who is carrying out the same attack against a bunch of other services at once, and virtually nothing to the few thousands of active users who shou…
Use rate limiting instead.
Re: Google's most ridiculous trick to force users into adding phone number
#118From your perspective, you're looking at a change that impacted you. From google's perspective, they're looking at a change which reduces phishing and scams by some small percent, and impacts a minuscule fraction of their users. Abuse, scams, phishing, and forgotten passwords are all significant problems which phone numbers help with. I'd be willing to bet these changes end up having an on net positive impact for goo…
Phone number is ultimate crossplatform and cross account identifier, only minority uses burner numbers for this. So I doubt that the phishing is the main driving motivation here, instead it is using phone numbers for easier tracking.
Re: Google's most ridiculous trick to force users into adding phone number
#119Earlier quoted context omitted.
at 25,000 login attempts per user if you're not doing common sense rate-limiting of attempts per username, and rate limiting per IP space origin (either discrete ipv4 /32 or attempts from within a whole ASN), you've got other problems. the rate-limit and blockage time for attempts should increase ban time/lockout-timer on an exponential time scale the more that a single browser/useragent/browser fingerprint/IP makes…
>yes obviously there are people out there with fully automated systems who will try massive lists of commonly used plaintext passwords for authentication if you don't throttle/rate-limit it. and those people use single browser/single useragent/single browser fingerprint/single IP the people competent enough to send millions of requests are usually also competent to send hard to detect requests there are dozens of (fr…
even if you see something like a single /32 address that is probably the public facing endpoint of a mobile phone carrier's cgnat and has MANY users behind it, trying different password attempts, you can still rate limit the number of attempts per unique username.
the actual amount of legit requests that a human who has forgot their password makes is 99.9% of the time under ten requests per account before they give up.
Re: Google's most ridiculous trick to force users into adding phone number
#120They call me about my car’s extended warranty every day whether google has my number or not. I also get a call, every day, precisely at 9:04am, from random numbers matching the first 6 digits of my phone number. Protecting my phone number is a dead effort on my end.