Live data from Hacker News

Google's most ridiculous trick to force users into adding phone number

news.ycombinator.com

181–190 of 250 posts

Re: Google's most ridiculous trick to force users into adding phone number

#181

Earlier quoted context omitted.

> Attackers are using hacked IoT devices to do these attacks. These devices have roughly the same computing power as a mid level smartphone. False for a very large variety of low-power IoT devices using chips like the ESP32, which are multiple decimal orders of magnitude slower than a modern computer (or high-end smartphone) and will absolutely take far longer to compute a Hash cash challenge than one of those device…

You have no idea what you're talking about. Botnets are almost entirely ISP router/modem combo devices. Hashcat was proposed over 20 years ago. You really think out of all the tens of thousands of security engineers working on this problem, nobody has ever considered it? Get a grip. I hate how this website incentivizes people to try to make posts that sound smart instead of posting stuff they're actually knowledgeabl…

This comment violates probably about a dozen different parts of the HN guidelines[1]. You should calm down with the ad-hominems and substance-less claims and give the guidelines a read, then come back and make an actual argument.

[1] https://news.ycombinator.com/newsguidelines.html

Re: Google's most ridiculous trick to force users into adding phone number

#182

Earlier quoted context omitted.

You have no idea what you're talking about. Botnets are almost entirely ISP router/modem combo devices. Hashcat was proposed over 20 years ago. You really think out of all the tens of thousands of security engineers working on this problem, nobody has ever considered it? Get a grip. I hate how this website incentivizes people to try to make posts that sound smart instead of posting stuff they're actually knowledgeabl…

> Botnets are almost entirely ISP router/modem combo devices. Above you say they are IoT devices. I don't mean 'gotcha', but to learn: What does the population of botnet devices consist of?

[deleted]

Re: Google's most ridiculous trick to force users into adding phone number

#183

the thing about 'adding a phone number' is that hijacking somebody's DID is fairly trivial these days for a good social engineer, you get the customer service department at somebody's cellular carrier to port out the number, or activate it on a new SIM card put into a burner. the SS7/PSTN is horribly broken. SMS based "2FA" is not actual 2FA

I think "trivial" is generous. For context, the current market rates for a SIM swap ranges from several thousand USD (T-Mobile) to well over fifty thousand USD (Verizon). It is not really something most people should lose sleep over, in my opinion.

That seems absurdly high for a SIM Swap. Source?

Re: Google's most ridiculous trick to force users into adding phone number

#184
I have a tangential story on how providing a phone number isn’t going to help either.

I have an important Gmail account where I recently had to change the password (because the only password set several years ago didn’t work). Since it was important, I didn’t want to risk the account becoming inaccessible and hence provided my phone number as the recovery number. After changing the password through a browser, the iOS Mail app complained that the password for this account is invalid and that I should enter it. So I go there and flow through the Google login pages (since this is setup as a Google account), and then it repeatedly tells me that it’s incorrect and that I should recover my account. Visiting the recover account page tells me that it cannot help me at this moment!

I’m furious at how stupid Gmail (and the people in Google writing this application) can be. I haven’t accessed that account over the last few days and am hoping I can get back in after the Google bots have cooled down. I have no idea what I can do if that account becomes permanently inaccessible because some “machine learning” algorithm messed things up. :(

I’ve decided to close my Gmail accounts (these were old ones) if I can manage to download the data from those.

Re: Google's most ridiculous trick to force users into adding phone number

#185

Every tech company is losing the war against credential stuffing. I have a friend working at a series B startup with None of the service providers who claim to fix the issue are worth their weight in salt. Shape, Akamai, none of them have a grip on the problem because the attackers are constantly evolving. As you can see, even Google is capitulating despite all the fud that people on HN spread about the company being…

This. This reminds me of a couple of other hot threads on HN like Google not allowing you to log back in to old dormant accounts. It's abundantly clear to me that it's the same thing, same motivation.

The world desperately needs to move away from username + passwords. Google might seem really pushy right now, but it's simply a trailblazer. My prediction: in a few years every company that handles valuable personal information will behave like what Google is doing today.

Re: Google's most ridiculous trick to force users into adding phone number

#186
post #6

It's not even about not willing to spend 1$ for a random phone number. Here's a list of things that are wrong with what Google does: - If you want to read your email, you have to use app specific password. I'm ok with that. - You can't generate app specific passwords if you don't have 2FA enabled. That's some artificial limitation made to force you into adding phone number to your account. - You can't use authenticat…

> It's not even about not willing to spend 1$ for a random phone number. Some sites (e.g. Scaleway.com) won't accept VOIP numbers: they require numbers from actual mobile networks. That is a pain for me since my main phone# is a VOIP number that forwards to my mobile. I do that so I can change my mobile number and just update the forwarding target, or can forward to a landline if I'm someplace with a lousy mobile sig…

get an ultra cheap prepaid line then cancel

some (like visible) allow you to sign up without providing any of your own PII

Re: Google's most ridiculous trick to force users into adding phone number

#187

Earlier quoted context omitted.

I bought Pixel phones for my wife and I because the price and ease of use to save my kids pictures was absolutely worth it. I haven't found a service that functions as well as Google Photos. She takes pics and I take pics, and we have a shared account that backs it all up without any messing about. I have done precisely ZERO tech support for my wife since buying this service and phones and I will probably never leave…

My dad hates his pixel. His impressions are that they are taking away useful functionality and replacing it with Google assistant. He said he keeps trying to disable Google assistant but it turns on again the next morning. I myself tried to power off the device. Holding the lock button actually didn't show a power off menu, it opened Google assistant. As far as I can tell the only way to turn off the phone was to say…

I am not justifying the decision, the power off button in the notification shade between quick toggles and notifications.

Re: Google's most ridiculous trick to force users into adding phone number

#188
post #46

Earlier quoted context omitted.

Google used to give more options before. Today if you want to set-up 2FA you must either give them a phone number or use a phone. Only then you can add other authentication methods (this a hardware key) and remove your phone as an option. Source: went through this nonsense a couple years ago and then again a couple months ago with a different account.

Man, this thread is such a shinning example of why "trust, but verify" is a phrase. There is ABSOLUTELY an option to enable 2FA on a Google account now that does not require giving them a phone number. There's a clear "Advanced Options" link that lets you choose a security key, which is what folks should be using anyway.

True, I just didn't write that because physical security key is not an option where I live.

Other than security key, it's only phone number or adding account to the phone.

I'm sorry I didn't mention that in my post, I wasn't trying to lie, I just can't obtain physical key and I don't think I have to have physical key to read my emails.

Re: Google's most ridiculous trick to force users into adding phone number

#189
post #89

Earlier quoted context omitted.

> You can't use authenticator app to enable 2FA Are you sure about that? I don't think this is true. I definitely don't have a phone number linked to my Google Account and I have TOTP enabled as well. They even have the Advanced Protection mode which doesn't allow SMS or the authenticator app. Really though, you should do the last thing. Buy some security keys and enable Advanced Protection.

This is correct. A phone number is NOT required to enable 2FA, at least in my experience within the last few months. I set up 2FA to use Yubikey hardware keys for a google account, and was then allowed to generated app passwords. No phone number has ever been attached to the account. I do agree that not allowing app-passwords to be generated without setting up 2FA is coercive and seems hard to justify, and it is plau…

You are right that I can bypass adding phone number if I have Yubikey, but unfortunately I don't have one and can't get it.

Re: Google's most ridiculous trick to force users into adding phone number

#190
post #159

Earlier quoted context omitted.

Only after you give them a phone number. In fact, they allow you to remove the phone number afterwards, so clearly they're happy with non-SMS 2FA being the only 2FA method on the account, as long as they first get the opportunity to stalk you beforehand.

Do they accept burner phone #s?

There's no universal definition of a burner phone number, but they do ban certain number ranges commonly associated with VoIP providers. Your best bet is to get a prepaid SIM as those typically draw from the main number pool of the carrier so scum like Google can't ban those without also banning a third of their target market.
Post reply on HN