Live data from Hacker News

Google's most ridiculous trick to force users into adding phone number

news.ycombinator.com

191–200 of 250 posts

Re: Google's most ridiculous trick to force users into adding phone number

#191
post #61
post #3

Earlier quoted context omitted.

Can you recommend me any real working website where I could buy cheap one time virtual number that could be used to enable 2FA for my account? And I hope they will never ever again ask me to confirm anything using that number.

I have used voip.ms for years. The basic plan costs approx 1 usd/m with no contracts, etc. and any messages received can be forwarded to and responded from email.

Nice try but this won't work with a lot of security providers.

Lookup APIs are available to identify line type and most will specifically reject voip numbers. The more obstinate providers I have encountered (some banks for example) will actually have a real human place a call to any number provided at sign up and reject it if they can't verbally talk to you.

Re: Google's most ridiculous trick to force users into adding phone number

#192
post #133

Earlier quoted context omitted.

If it fits your need to have it a fixed location, then yes. But he talked about traveling. IDK about you but I don't travel with a safe in my backpack

Just put it in your wallet and/or luggage. Without your account name and password, it's useless to any potential thief.

Lots of people's luggage include enough info to work out their name and likely home location, which is commonly enough to work out their username for a lot of popular services.

That makes the whole "stolen luggage" thing even far riskier. :/

Re: Google's most ridiculous trick to force users into adding phone number

#193
post #189
post #89

Earlier quoted context omitted.

This is correct. A phone number is NOT required to enable 2FA, at least in my experience within the last few months. I set up 2FA to use Yubikey hardware keys for a google account, and was then allowed to generated app passwords. No phone number has ever been attached to the account. I do agree that not allowing app-passwords to be generated without setting up 2FA is coercive and seems hard to justify, and it is plau…

You are right that I can bypass adding phone number if I have Yubikey, but unfortunately I don't have one and can't get it.

use virtual authenticator (https://developer.chrome.com/docs/devtools/webauthn/)

Re: Google's most ridiculous trick to force users into adding phone number

#194
post #55

I too was hit by this a few months ago, after having to create a Google account for work, and worked around it by running an android emulator where I installed their authenticator app. This was enough to get past the stupid "you have to have a phone" requirement, and gave me access to the TOTP secret, which I then promptly added to my favourite open source 2FA utility. Screw you, Google, you're not getting my phone n…

I might do this (install an emulator and use auth app there) if I can successfully login from it, I just need a lot of time to do that (internet here is really slow).

I asked one of my friends with faster internet to do that for me but google blocked an attempt to login with correct username and password.

Re: Google's most ridiculous trick to force users into adding phone number

#195

The Fair Email FAQ [1] states that it supports Google's OAuth, so why don't you authenticate with that? "OAuth for Gmail is supported via the quick setup wizard. The Android account manager will be used to fetch and refresh OAuth tokens for selected on-device accounts. OAuth for non on-device accounts is not supported because Google requires a yearly security audit ($15,000 to $75,000) for this. You can read more abo…

Because I'm using a fork that is not signed by Google and it can't use OAuth, unfortunately.

Re: Google's most ridiculous trick to force users into adding phone number

#197

Earlier quoted context omitted.

>yes obviously there are people out there with fully automated systems who will try massive lists of commonly used plaintext passwords for authentication if you don't throttle/rate-limit it. and those people use single browser/single useragent/single browser fingerprint/single IP the people competent enough to send millions of requests are usually also competent to send hard to detect requests there are dozens of (fr…

if you're sending millions of requests you still have a finite number of proxies to use, it would be thousands to tens of thousands of requests per discrete /32 ipv4 proxy address, and not hard to detect as an abnormal volume of attempts per IP. even if you see something like a single /32 address that is probably the public facing endpoint of a mobile phone carrier's cgnat and has MANY users behind it, trying differe…

And that "finite number" is tens of millions, or even hundred of millions, spread across providers, spread across almost any location. From 4G proxy farms, to botnets of residential IPs, to grey area apps that rewards user for sharing their connection.

And ok, let's assume it came from the same block of ips(which rarely happens) what do you do when those IP blocks are from IDK, Verizon or AT&T in the middle of New York?You block half the city?

+if the attacker is trying it on all accounts, what are you gonna do? rate limit all accounts? and now anytime a user forgot his password he have to contact support because he can't even do it himself so your support is overwhelmed by 1000s of request every day?

Re: Google's most ridiculous trick to force users into adding phone number

#198

Earlier quoted context omitted.

Unfortunately, what Google embeds into Android software is significantly more adverse than just "shellac". A standard Android phone sends your IMEI and SIM card info to Google servers on boot up before you even have a chance to login.

My phone won't even connect to cellular data until I log on after boot.

What the UI shows you and what the phone OS actually does are not necessarily the same.

Re: Google's most ridiculous trick to force users into adding phone number

#199
post #46

Earlier quoted context omitted.

Google used to give more options before. Today if you want to set-up 2FA you must either give them a phone number or use a phone. Only then you can add other authentication methods (this a hardware key) and remove your phone as an option. Source: went through this nonsense a couple years ago and then again a couple months ago with a different account.

Man, this thread is such a shinning example of why "trust, but verify" is a phrase. There is ABSOLUTELY an option to enable 2FA on a Google account now that does not require giving them a phone number. There's a clear "Advanced Options" link that lets you choose a security key, which is what folks should be using anyway.

use virtual authenticator (https://developer.chrome.com/docs/devtools/webauthn/)

Re: Google's most ridiculous trick to force users into adding phone number

#200
post #153

Shame HN is 80% tropes now from paranoid introverts who don't want to go back to the office and who could write Dropbox in half an hour

It's painfully obvious that a non trivial number of users here maintain little contact to ordinary people who make up 99% of the user base.

Whats painfully obvious is how people and profit and interchanged so seemlessly by the vultures who pray on the "ordinary people" and how desensitised we have become as a collective to the notion.

What HN shows is that a non-trivial amount of peoples entire life is focused on exploiting others inadequacies and this exploitation is portrayed as "normal" by those who profit and abormal by those who now see how invasive ad companies become.

Letting your child sit through an ad is akin to child abuse in my head. Like taking them to a church.

Post reply on HN