Live data from Hacker News

Google's most ridiculous trick to force users into adding phone number

news.ycombinator.com

201–210 of 250 posts

Re: Google's most ridiculous trick to force users into adding phone number

#201
post #132

Here is how I solved the same problem a couple of weeks ago. If you still have an active session in a browser, you can add a recovery e-mail address to you account security settings. After that I was able to add a Yubikey as a second factor without adding a phone number. This should also work if you want to use TOTP as a 2F instead of a Yubikey.

I might try this, thanks.

Yes, I do have session in my browser and I would use it as a second factor to manually approve every login to my account from my browser if I had option to do that, but Google doesn't allow that. You can only confirm logins from android or apple device.

Re: Google's most ridiculous trick to force users into adding phone number

#202
post #146

If all you need is IMAP/SMTP you can use this local proxy to continue using the “less secure” app without needing app passwords: https://github.com/simonrob/email-oauth2-proxy

That looks like a really great option for me, thanks a lot for the link.

Re: Google's most ridiculous trick to force users into adding phone number

#203
post #159

Earlier quoted context omitted.

Do they accept burner phone #s?

There's no universal definition of a burner phone number, but they do ban certain number ranges commonly associated with VoIP providers. Your best bet is to get a prepaid SIM as those typically draw from the main number pool of the carrier so scum like Google can't ban those without also banning a third of their target market.

> so scum like Google

You do know it isnt mandatory to be a customer.

Re: Google's most ridiculous trick to force users into adding phone number

#204
post #6

It's not even about not willing to spend 1$ for a random phone number. Here's a list of things that are wrong with what Google does: - If you want to read your email, you have to use app specific password. I'm ok with that. - You can't generate app specific passwords if you don't have 2FA enabled. That's some artificial limitation made to force you into adding phone number to your account. - You can't use authenticat…

The worst part about this 2FA story is that if you don't have any 2FA methods, Google will effectively lock you out of your account if you're trying to log in from an "unusual" device, i.e. any public (school, library) computer or wireless access point. If you don't have a phone with the proprietary google apps installed and logged into your account, you literally can't login in such situations. Make sure you always have a computer/OS combination that's recognized by google when you travel.

I used to constantly get emails about suspicious logins detected simply from moving around hotspots with my phone trying to log into IMAP. This was until I enabled the app password thing, which generated a password that's both shorter and uses less different characters than my old IMAP password.

Re: Google's most ridiculous trick to force users into adding phone number

#205
post #123

Google is no saint, but there's absolutely no reason to ascribe ill intent to collecting phone numbers of 2FA setup. The reason is simple: Google has billions of users, and at any given time, a lot of them break their devices and lose access to 2FA credentials. Phone numbers, despite all their flaws, are still the most reliable long-term and mostly-immutable attributes which can service as a proxy for identity which…

> Phone numbers, despite all their flaws, are still the most reliable long-term How so? The most realiable one is email, as it doesn't need to be tied to any third party so it can exist a lifetime. I've had the same email since the mid 90s. I've had probably a dozen or more phone numbers in that timeframe. A handful of which are still tied to various company accounts even though I've long since haven't had any acces…

I've had the same phone number since the mid 90s. I've had probably a dozen or more email addresses in that timeframe. A handful of which are still tied to various company accounts even though I've long since haven't had any acces to those email accounts.

Re: Google's most ridiculous trick to force users into adding phone number

#206
post #55

I too was hit by this a few months ago, after having to create a Google account for work, and worked around it by running an android emulator where I installed their authenticator app. This was enough to get past the stupid "you have to have a phone" requirement, and gave me access to the TOTP secret, which I then promptly added to my favourite open source 2FA utility. Screw you, Google, you're not getting my phone n…

What's your favorite open source 2FA utility?

https://www.nongnu.org/oath-toolkit/oathtool.1.html with some very light shell wrapper around it.

Re: Google's most ridiculous trick to force users into adding phone number

#207
post #201
post #132

Here is how I solved the same problem a couple of weeks ago. If you still have an active session in a browser, you can add a recovery e-mail address to you account security settings. After that I was able to add a Yubikey as a second factor without adding a phone number. This should also work if you want to use TOTP as a 2F instead of a Yubikey.

I might try this, thanks. Yes, I do have session in my browser and I would use it as a second factor to manually approve every login to my account from my browser if I had option to do that, but Google doesn't allow that. You can only confirm logins from android or apple device.

It worked for me and I did not have to give Google my phone number to "unlock" the other 2FA options and subsequently app passwords. I used the Yubikey, but I think it should work if you only use TOTP.

Re: Google's most ridiculous trick to force users into adding phone number

#208
post #98
post #55

I too was hit by this a few months ago, after having to create a Google account for work, and worked around it by running an android emulator where I installed their authenticator app. This was enough to get past the stupid "you have to have a phone" requirement, and gave me access to the TOTP secret, which I then promptly added to my favourite open source 2FA utility. Screw you, Google, you're not getting my phone n…

Which android emulator do you use ?

I looked around for a least invasive solution, and went with https://www.android-x86.org/ in a small virtual machine.

Re: Google's most ridiculous trick to force users into adding phone number

#209

Google is no saint, but there's absolutely no reason to ascribe ill intent to collecting phone numbers of 2FA setup. The reason is simple: Google has billions of users, and at any given time, a lot of them break their devices and lose access to 2FA credentials. Phone numbers, despite all their flaws, are still the most reliable long-term and mostly-immutable attributes which can service as a proxy for identity which…

There’s nothing that says they absolutely must do things at a scale that leads to ethical compromises. Oh, other than greed, that is.

Re: Google's most ridiculous trick to force users into adding phone number

#210
post #6

It's not even about not willing to spend 1$ for a random phone number. Here's a list of things that are wrong with what Google does: - If you want to read your email, you have to use app specific password. I'm ok with that. - You can't generate app specific passwords if you don't have 2FA enabled. That's some artificial limitation made to force you into adding phone number to your account. - You can't use authenticat…

> You can't use authenticator app to enable 2FA Are you sure about that? I don't think this is true. I definitely don't have a phone number linked to my Google Account and I have TOTP enabled as well. They even have the Advanced Protection mode which doesn't allow SMS or the authenticator app. Really though, you should do the last thing. Buy some security keys and enable Advanced Protection.

True for few years now
Post reply on HN