Live data from Hacker News

Tell HN: I can't login to Gmail due to phone cannot be used for verification

news.ycombinator.com

41–48 of 48 posts

Re: Tell HN: I can't login to Gmail due to phone cannot be used for verification

#41

This phone verification shit is so awful. I have two friends who moved overseas and disconnected their cellphone plans without thinking about their MFA situation. Today I have to enforce MFA at the small company I'm working at, and just a month prior I held a cybersecurity seminar for them and explained that "phone MFA is… okay… but you should really use verification apps." But I didn't realize that you can't even en…

> just infuriating.

I just bought a prepaid card only for this - Google, Facebook, Twitter, Instagram. I don't use it for anything else. I took it out and hope to remember to top it up for another year to keep it in service. It's so stupid.

Re: Tell HN: I can't login to Gmail due to phone cannot be used for verification

#43
post #5

This phone verification shit is so awful. I have two friends who moved overseas and disconnected their cellphone plans without thinking about their MFA situation. Today I have to enforce MFA at the small company I'm working at, and just a month prior I held a cybersecurity seminar for them and explained that "phone MFA is… okay… but you should really use verification apps." But I didn't realize that you can't even en…

So I have used Authy, which apparently is somehow protocol compatible with Google Authenticator, and you can back up your tokens with a password. I got a new phone, installed the app, entered the password, and all my tokens were there.

The problem is that one has to enable phone MFA before they can enable Authy/other-app MFA. I have no idea why, only theory I can come up with is the value of tying accounts to outside marketing databases using phone numbers as IDs.

Re: Tell HN: I can't login to Gmail due to phone cannot be used for verification

#45
Recently had a close call where my phone screen was dead (no display, no blind touch input either) and I was away from home where I did just happen to have an old android tablet that was "known" to google.

It was not as bad as that guy that Google totally F'd because of the pictures of his kid's genitals that his doctor requested, where he had a google fi phone and gmail email etc. He had no ways around at all. But still scary enough.

I almost couldn't even just buy a new phone to regain access to txt, because Ting web site forces you to enable 2fa, and I had it using google authenticator on the same phone.

So I couldn't receive txt verification codes, couldn't respond to google's "yes it's me" thing, couldn't use my authenticator app to access my account on Ting to move my number to another device so I could receive txts...

Luckily, I HAD saved the recovery codes from Ting and I had those in my keepass db which I have many ways to access, so I was able to use that to get in to the Ting acct if I needed to move the number to a new device. (plus I just now remembered this phone has a removable sim card so maybe I could have moved the number that way, but what if the phone had been esim?)

In the end, I was able to get the screen replaced at a local shop without resetting the phone, so I regained access to the pre-existing Authenticator install, and regained ability to repond to google's "yes it's me" on the previously recognized device.

And if the phone had been unrepairable, I would have been able to move my number to a new device and eventually recover everything else by txt because I did have a way to get into my Ting acct.

I had a lot of non-critical things registered with a gmail acct for convenience, but the important things I use a mix of other emails with gmail also as a backup, but a few of the most important things were using google authenticator and I didn't have a 2nd authenticator app up & running on any other device, and didn't know about exporting the original seed when I first set it up so I couldn't just fire up some other new device and install an auth app and start using it.

I DID have single-use recovery codes for some sites saved in my keepass db, but not all.

So after this wake-up call, I was able to use my old phone to get into everything and re-do the 2fa on everything.

I found I could use Gnome Authenticator app on my laptop, and export the seed tokens and save a json text blob in my keepass, and verified that I can take a brand new laptop, install keepassxc and gnome authenticator, import that json, and successfully use the brand new machine to access the 2fa-protected sites without needing my existing phone or laptop, and without needing access to any google acct. I do have gmail as a backup email for things where protonmail or something else is the primary.

I also keep the single-use emergency codes for each individual site in keepass as well as printed just because "why not?" though I really don't imagine the print copies ever being used.

So all I need is access to any copy of my keepass db (which I can scatter around at will and can access any number of ways, thumb drives, home nas, google drive, random vps, copies on devices, etc, so I do NOT need access to a google drive or onedrive etc to retrieve it) And everything else can be reconstructed from new downloads of all purely open source software and the keepass db password.

But what struck me is how it's really up to the user to deviate from the easy path and go way out of their way to be safe. They are not safe by default if they just do what google says all along the way. By default, google will happily make themselves a single point of failure for your entire life, which is easily tripped and provides no channels for correcting errors.

On-line-only banking/investing accts with no local physical office are particularly scary, when they do not know you any other way than by your login. You can't go down to the office and show the manager your birth certificate or passport or drivers license or idk thumbprint? etc. That's your life savimgs, your house, everything, all hanging by something that is easily broken and impossible to fix.

Re: Tell HN: I can't login to Gmail due to phone cannot be used for verification

#46
post #5

This phone verification shit is so awful. I have two friends who moved overseas and disconnected their cellphone plans without thinking about their MFA situation. Today I have to enforce MFA at the small company I'm working at, and just a month prior I held a cybersecurity seminar for them and explained that "phone MFA is… okay… but you should really use verification apps." But I didn't realize that you can't even en…

So I have used Authy, which apparently is somehow protocol compatible with Google Authenticator, and you can back up your tokens with a password. I got a new phone, installed the app, entered the password, and all my tokens were there.

I just installed Authy on my other Android phone and I need to login with my "phone number".... WTF...?

Re: Tell HN: I can't login to Gmail due to phone cannot be used for verification

#47
post #46
post #5

Earlier quoted context omitted.

So I have used Authy, which apparently is somehow protocol compatible with Google Authenticator, and you can back up your tokens with a password. I got a new phone, installed the app, entered the password, and all my tokens were there.

I just installed Authy on my other Android phone and I need to login with my "phone number".... WTF...?

use aegis or keepassXC/Keepassium/Keepass2Android. These apps allow to keep (backups of) your (T)OTP secrets offline and don't require additional PII info to set up.

Re: Tell HN: I can't login to Gmail due to phone cannot be used for verification

#48
post #19

What worked for me was to try it again from an IP I had logged in with before. For some reason it causes Gmail to not ask for a phone number verification. Once logged in I could change the phone number. Really stupid way to do it. No reason to lock someone out with the right password. A better alternative would be to show partial digits of an old number and ask you to complete it.

Yes, I solved it the same way (I no longer had access to my old phone number) and promptly setup google authenticator (well actually stored the totp string in 1password) and got backup codes. I'm lucky that I have a server in the US that I regularly use as a VPN so I could try again from a known ip.

In my case, it wasn't from the exact same IP, but rather the same city. Apparently google uses IP location as a risk-factor as well.
Post reply on HN