Live data from Hacker News

Google's most ridiculous trick to force users into adding phone number

news.ycombinator.com

161–170 of 250 posts

Re: Google's most ridiculous trick to force users into adding phone number

#161

Google is no saint, but there's absolutely no reason to ascribe ill intent to collecting phone numbers of 2FA setup. The reason is simple: Google has billions of users, and at any given time, a lot of them break their devices and lose access to 2FA credentials. Phone numbers, despite all their flaws, are still the most reliable long-term and mostly-immutable attributes which can service as a proxy for identity which…

This is an explanation for why Google might ask for phone numbers. This is not an explanation for why Google might require phone numbers. The only valid reasons for the latter are (1) to collect your PII and/or (2) because they think that they know better than you and they're going to force you to do a thing because they think it's in your best interests - in other words, a tyrant ruling over a techno-feudalistic soc…

Why might Google require it?

It adds an external cost to creating an account. I imagine this is incredibly valuable in fighting spam across all of their services. No coincidence, the phone number requirement is the only reason I don't have several disposable twitter, Facebook, and Google accounts.

Re: Google's most ridiculous trick to force users into adding phone number

#162

Earlier quoted context omitted.

Shellac is just a varnish/coating, so the implication is Google features are metaphorically painted on the phone hardware and software and you just need to scrape it off.

Unfortunately, what Google embeds into Android software is significantly more adverse than just "shellac". A standard Android phone sends your IMEI and SIM card info to Google servers on boot up before you even have a chance to login.

My phone won't even connect to cellular data until I log on after boot.

Re: Google's most ridiculous trick to force users into adding phone number

#163
post #152
post #68

Earlier quoted context omitted.

I've tried that a few days ago. You always need to add a phone as your first MFA method. A simple hack though:you can add other methods, then remove phone. Your account was likely created before phone MFA was mandatory (as the first method).

> A simple hack though:you can add other methods, then remove phone. Sure. That's like when I deleted my DigitalOcean account. They still send me notices about their service. Just because something is deleted for you doesn't mean it's deleted for them .

well said!

Re: Google's most ridiculous trick to force users into adding phone number

#164
post #6

It's not even about not willing to spend 1$ for a random phone number. Here's a list of things that are wrong with what Google does: - If you want to read your email, you have to use app specific password. I'm ok with that. - You can't generate app specific passwords if you don't have 2FA enabled. That's some artificial limitation made to force you into adding phone number to your account. - You can't use authenticat…

> It's not even about not willing to spend 1$ for a random phone number.

Some sites (e.g. Scaleway.com) won't accept VOIP numbers: they require numbers from actual mobile networks. That is a pain for me since my main phone# is a VOIP number that forwards to my mobile. I do that so I can change my mobile number and just update the forwarding target, or can forward to a landline if I'm someplace with a lousy mobile signal, etc. All of this sucks.

Re: Google's most ridiculous trick to force users into adding phone number

#165
post #6

It's not even about not willing to spend 1$ for a random phone number. Here's a list of things that are wrong with what Google does: - If you want to read your email, you have to use app specific password. I'm ok with that. - You can't generate app specific passwords if you don't have 2FA enabled. That's some artificial limitation made to force you into adding phone number to your account. - You can't use authenticat…

> It's not even about not willing to spend 1$ for a random phone number. Some sites (e.g. Scaleway.com) won't accept VOIP numbers: they require numbers from actual mobile networks. That is a pain for me since my main phone# is a VOIP number that forwards to my mobile. I do that so I can change my mobile number and just update the forwarding target, or can forward to a landline if I'm someplace with a lousy mobile sig…

It's also not unheard of to enter a valid phone number and get a message that the number has been used too many times and is no longer valid for 2FA.

Re: Google's most ridiculous trick to force users into adding phone number

#166

Earlier quoted context omitted.

There are far better ways to stop credential stuffing than requiring a phone number that would be immediately obvious to the people at Google - Hashcash, for instance[1]. 250M login attempts times a few seconds of CPU time is a lot of compute cost to inflict on an attacker who is carrying out the same attack against a bunch of other services at once, and virtually nothing to the few thousands of active users who shou…

The problem with proof-of-work-for-login is: Some of your attackers are going to run your proof-of-work algorithm on a 3090 Ti GPU and put loads of work into optimising their setup. Some of your legitimate users are going to run it on a Raspberry Pi 1 with an ancient browser that only runs wasm through a javascript polyfill. Tough to make up for a 1000x performance difference.

Then give those users an option. It's not hard. Show a little progress bar for the PoW, and then offer the user other options including manually approving the new logon and using a yubikey or similar.

Re: Google's most ridiculous trick to force users into adding phone number

#169
post #10

Earlier quoted context omitted.

I have a small free VPS and free domain name (whatever.duckdns.org). Do you think I can make a mail server that works, that could send emails that won't end up in spam folder of other people, and that I could use to create accounts? I have thoughts of running my own mail server, but a lot of sites just won't let you create an account if you don't provide «trusted» email, and by «trusted» most of the time they mean gm…

small fee VPS are likely to be in IP space that has a 'bad' reputation from other people who have historically done dumb things in the same /24 or /22, etc, even if it looks clean from RBL checking tools, you have no idea what its reputation is for actual delivery to google and office365.

Nothing you do excepting buying your email service from the same-self megacorps will protect you from the megacorps whim and mistakes (and even then not all the time). As you and others have mentioned, even relatively large companies get blocked.

We have to be the changes we want to see in the world. Maybe don't use the domain/mailserver for life or death services the first few years and just see how it goes.

Re: Google's most ridiculous trick to force users into adding phone number

#170
post #46

Earlier quoted context omitted.

Google used to give more options before. Today if you want to set-up 2FA you must either give them a phone number or use a phone. Only then you can add other authentication methods (this a hardware key) and remove your phone as an option. Source: went through this nonsense a couple years ago and then again a couple months ago with a different account.

Man, this thread is such a shinning example of why "trust, but verify" is a phrase. There is ABSOLUTELY an option to enable 2FA on a Google account now that does not require giving them a phone number. There's a clear "Advanced Options" link that lets you choose a security key, which is what folks should be using anyway.

Almost nobody in the world have physical key and they shouldn't need to buy one when 2fa apps are sufficient for most people.
Post reply on HN