Live data from Hacker News

Adding a phone number to your Google account can make it less secure

tech.vijayp.ca

41–50 of 299 posts

Re: Adding a phone number to your Google account can make it less secure

#41
post #4

I don't think it's possible to make a Google account without a phone number anymore. It's really unfortunate, especially because I deliberately don't set up fallback contacts for my "alternate" gmail accounts, and Google keeps locking them as suspicious when I log in from a second location, and I need to "verify" with a phone number any time that happens (at which point I abandon the account). I understand that they…

I think the main issue is that google doesn't accept certain senders anymore. As a generic thread about running a mailserver/mail service pops up here often. That means users are shoveled into about one of 4 "acceptable" providers which have control of the entire market. They demand, full name and usually gender, mobile, alternative email and more. So you get pushed into their information pipeline to stop "spam".

It accepts my personal mail server just fine. You need to support encryption, spf, and dkim but mail will flow no problem to gmail users in my experience.

Re: Adding a phone number to your Google account can make it less secure

#42
post #4

I don't think it's possible to make a Google account without a phone number anymore. It's really unfortunate, especially because I deliberately don't set up fallback contacts for my "alternate" gmail accounts, and Google keeps locking them as suspicious when I log in from a second location, and I need to "verify" with a phone number any time that happens (at which point I abandon the account). I understand that they…

I think the main issue is that google doesn't accept certain senders anymore. As a generic thread about running a mailserver/mail service pops up here often. That means users are shoveled into about one of 4 "acceptable" providers which have control of the entire market. They demand, full name and usually gender, mobile, alternative email and more. So you get pushed into their information pipeline to stop "spam".

Yep, I wrote one not too long ago:

http://penguindreams.org/blog/how-google-and-microsoft-made-...

I've been meaning to write a follow up after I met some MailChip devs at a conference. They told me at MailChip they have to slowly spin up new servers, sending e-mail through them slowly so Google registers their new SMTP IPs.

The other thing they told me: MailChip owns a /A, and can therefore separately out their servers from even being remotely related to any spammy subnets (common problem on 'cloud' hosting).

I'm wondering if I heard/remember that correctly. I mean, a class A is huge and would be crazy expensive. I've been looking through websites on ASNs and am trying to figure out how to verify that info.

Re: Adding a phone number to your Google account can make it less secure

#43
Huh. I wonder if the author had seen this video https://m.youtube.com/watch?v=Q00OZ_Xk24w which describes a similar story and recommends a solution based on the same factors (2FA on a number no one knows under a fake name).

But anyway I don't understand why he thinks it's some kind of shocker that this makes it less secure. It's another access method. Recovery options are obviously attack vectors.

Re: Adding a phone number to your Google account can make it less secure

#44
post #26

Earlier quoted context omitted.

This is why last weekend I moved to FastMail. I've filed two support tickets since, and both were responded to in an hour or two. For the trivial cost of half a Netflix subscription, the most vital thing I have on the Internet is supported by real people. It's hard to justify Gmail these days other than the frustration of migrating off of it. As a side perk, Australia has no equivalent to a National Security Letter,…

> This is why last weekend I moved to FastMail. I've filed two support tickets since, and both were responded to in an hour or two. Can absolutely confirm that. However, there's place for both Gmail and FastMail. Just know what you pay and what you're entitled to get for that price.

For me the issue is transitioning from something like gmail to my own email. I've had the account for 12 years at this point.

Re: Adding a phone number to your Google account can make it less secure

#45
post #11

I've also noticed that there's something very surprising about how Google has implemented their 2FA. When I log into Gmail from a new computer, it does not text me an authentication code and then lock me out of the account until I enter the code. Instead it lets me into my account immediately with only a password, and then sends my phone a notification that someone has logged in from a new computer. Ignoring this not…

I can confirm that that's what happens to your account when you dont have 2FA enabled. Can you double check your settings?

I'm on mobile right now, and I don't see a way to check 2FA status from within the Gmail app. I can confirm that I've had it set up correctly before, as I've received an authentication code from Google as recently as September 28.

Re: Adding a phone number to your Google account can make it less secure

#46

>Eventually, with the help of Google’s customer support and some ex-colleagues who still work at Google, Bob was able to get his account back. I bet I know which one of these resources was more important.

I bet I know which one of those resources actually exists.

Re: Adding a phone number to your Google account can make it less secure

#47
Does anyone know anything about the security with regard to using other providers (e.g. twilio or google voice) as a recovery number?

Let's say my recovery number is actually a google voice number that's connected to a separate google account, but not forwarded to my actual cellphone (i.e., I'd have to login to my other google account to view the recovery code). Thoughts?

Re: Adding a phone number to your Google account can make it less secure

#48
post #14

Can Americans explain me how can you just do things like that by calling customer support? Wouldn't it make more sense to go and show your ID if you want to make changes like that?

Where would you go to show ID? In many places in America, the closest telco customer service office may be a 2 hour drive away. Everyone saves time/money by being able to do it over the phone; but unfortunately the customer service reps are usually poorly trained.

Training shouldn't really be a factor here. The software systems shouldn't let social engineering hacks work. Why is the customer service rep allowed to override whatever prompt ask for a PIN number? If this override is really needed it should be a higher ranking support member or manager who can do this.

Re: Adding a phone number to your Google account can make it less secure

#49
post #12

> I'm curious [...] why Google doesn’t temporarily disable accounts so impacted until a human reviews activity. Because Google doesn't have humans reviewing anything unless there's a direct link to marginal revenue/cost avoidance attached to that interaction that can be priced in. Their business model is to achieve scale through automation and machine learning; which means not doing things that would require manual i…

You know, you can see articles where people report social engineering attacks on Amazon customer service and extract a great deal of information from them.

Having a human involved is not necessarily a solution, can be another attack vector.

Re: Adding a phone number to your Google account can make it less secure

#50

Earlier quoted context omitted.

The problem with the backup codes is that I have so many now. Pretty much a list of codes for every account I have 2FA enabled on (about a dozen). If I actually printed them out and kept them in my wallet, my wallet would be overflowing by now. Authy has been a great improvement over Google Authenticator for me. I primarily used it when I migrated phones for the upteenth time, but were I to lose my phone, I could als…

Put your recovery codes on an offline SD card somewhere safe in your house. I keep mine in a literal safe.

SD cards don't last forever. I've had 3 different cards seemingly randomly corrupt in different devices on me. I don't trust them to hold anything important for long.
Post reply on HN