Live data from Hacker News

Google's most ridiculous trick to force users into adding phone number

news.ycombinator.com

81–90 of 250 posts

Re: Google's most ridiculous trick to force users into adding phone number

#81

the thing about 'adding a phone number' is that hijacking somebody's DID is fairly trivial these days for a good social engineer, you get the customer service department at somebody's cellular carrier to port out the number, or activate it on a new SIM card put into a burner. the SS7/PSTN is horribly broken. SMS based "2FA" is not actual 2FA

I think "trivial" is generous. For context, the current market rates for a SIM swap ranges from several thousand USD (T-Mobile) to well over fifty thousand USD (Verizon). It is not really something most people should lose sleep over, in my opinion.

I classify it as trivial compared to the effort in breaking some real 2FA or otherwise hijacking the start of authority for somebody's online identity/ability to reset their passwords and gain access to an account, like getting possession of a personal domain name to change the authoritative nameservers, set a new MX and receive incoming password-reset emails.

Working in the telecom industry I've seen the pressures that first tier phone service reps are under and how they can be socially engineered, if someone is in possession of enough pieces of a person's identity already, to issue a new SIM or port out a number.

Re: Google's most ridiculous trick to force users into adding phone number

#82
post #6

It's not even about not willing to spend 1$ for a random phone number. Here's a list of things that are wrong with what Google does: - If you want to read your email, you have to use app specific password. I'm ok with that. - You can't generate app specific passwords if you don't have 2FA enabled. That's some artificial limitation made to force you into adding phone number to your account. - You can't use authenticat…

> You can't use authenticator app to enable 2FA Are you sure about that? I don't think this is true. I definitely don't have a phone number linked to my Google Account and I have TOTP enabled as well. They even have the Advanced Protection mode which doesn't allow SMS or the authenticator app. Really though, you should do the last thing. Buy some security keys and enable Advanced Protection.

It is true, I have recently looked everywhere. You can't enable choose TOTP with only a desktop web browser.

I'm really glad that I've never used a gmail address for email before, I'd hate to be stuck with using anything run by Google.

Re: Google's most ridiculous trick to force users into adding phone number

#83

Every tech company is losing the war against credential stuffing. I have a friend working at a series B startup with None of the service providers who claim to fix the issue are worth their weight in salt. Shape, Akamai, none of them have a grip on the problem because the attackers are constantly evolving. As you can see, even Google is capitulating despite all the fud that people on HN spread about the company being…

There are far better ways to stop credential stuffing than requiring a phone number that would be immediately obvious to the people at Google - Hashcash, for instance[1]. 250M login attempts times a few seconds of CPU time is a lot of compute cost to inflict on an attacker who is carrying out the same attack against a bunch of other services at once, and virtually nothing to the few thousands of active users who shou…

Attackers are using hacked IoT devices to do these attacks. These devices have roughly the same computing power as a mid level smartphone. Attackers do not use their own hardware, and don't care about how much energy is used by their bot devices.

In a normal attack, there are maybe 2-3 requests per hour that come from each hacker-owned device. The only thing that hashcat would do is drastically increase power consumption at no cost to the attacker, and turn the application into a battery drainer on mobile devices.

So no, Hashcat is not an adequate solution.

Re: Google's most ridiculous trick to force users into adding phone number

#84
post #30

Earlier quoted context omitted.

not only lost phone, but damaged phone is enough, as you can easily swap sim card but authenticator need to be set up again. BUT there are also one time recovery codes, they could add you option to use those to recover after clicking through few screens of warnings to make sure that you know what consequences does it have

That's one reason I definitely prefer SMS auth to any other method at the moment. What if your phone is damaged while traveling and you are away from where you stored your recovery keys?

You can always bring a paper recovery code or FIDO authenticator (both of which are safe against SIM swapping attacks).

Re: Google's most ridiculous trick to force users into adding phone number

#85
For some time now it has been necessary to first setup a phone number as the 2FA solution on a Google account. Only after doing that does it become possible to setup alternative 2FA solutions.

So every account I setup, I have to temporarily provide my phone number to enable 2FA, then setup authy, and then delete my phone number. Obviously Google now knows who the real user is, but I haven't been creating additional accounts to be secret. That doesn't excuse the system, but it's not more than a small hassle for me.

Re: Google's most ridiculous trick to force users into adding phone number

#86
post #46

Earlier quoted context omitted.

> You can't use authenticator app to enable 2FA Are you sure about that? I don't think this is true. I definitely don't have a phone number linked to my Google Account and I have TOTP enabled as well. They even have the Advanced Protection mode which doesn't allow SMS or the authenticator app. Really though, you should do the last thing. Buy some security keys and enable Advanced Protection.

Google used to give more options before. Today if you want to set-up 2FA you must either give them a phone number or use a phone. Only then you can add other authentication methods (this a hardware key) and remove your phone as an option. Source: went through this nonsense a couple years ago and then again a couple months ago with a different account.

You can start with a hardware key: https://i.imgur.com/FIjNyIh.png

Re: Google's most ridiculous trick to force users into adding phone number

#87

I guess I'll just have to stop using google. Welcome to the club. The fastest way to convince me *not* to use a product is to attach a "Google" label to it. Nothing Google has to offer justifies the drawbacks. NOTE: I do use an Android phone --- but only after it has been thoroughly de-Googled --- starting from a stripped down, bare metal device that won't even power up.

I bought Pixel phones for my wife and I because the price and ease of use to save my kids pictures was absolutely worth it. I haven't found a service that functions as well as Google Photos. She takes pics and I take pics, and we have a shared account that backs it all up without any messing about. I have done precisely ZERO tech support for my wife since buying this service and phones and I will probably never leave…

How do you see eachothers photos though?

Re: Google's most ridiculous trick to force users into adding phone number

#88

Earlier quoted context omitted.

I bought Pixel phones for my wife and I because the price and ease of use to save my kids pictures was absolutely worth it. I haven't found a service that functions as well as Google Photos. She takes pics and I take pics, and we have a shared account that backs it all up without any messing about. I have done precisely ZERO tech support for my wife since buying this service and phones and I will probably never leave…

Amazon Photos

I would not trust Amazon with tech related stuff lol

Re: Google's most ridiculous trick to force users into adding phone number

#89
post #6

It's not even about not willing to spend 1$ for a random phone number. Here's a list of things that are wrong with what Google does: - If you want to read your email, you have to use app specific password. I'm ok with that. - You can't generate app specific passwords if you don't have 2FA enabled. That's some artificial limitation made to force you into adding phone number to your account. - You can't use authenticat…

> You can't use authenticator app to enable 2FA Are you sure about that? I don't think this is true. I definitely don't have a phone number linked to my Google Account and I have TOTP enabled as well. They even have the Advanced Protection mode which doesn't allow SMS or the authenticator app. Really though, you should do the last thing. Buy some security keys and enable Advanced Protection.

This is correct. A phone number is NOT required to enable 2FA, at least in my experience within the last few months.

I set up 2FA to use Yubikey hardware keys for a google account, and was then allowed to generated app passwords. No phone number has ever been attached to the account.

I do agree that not allowing app-passwords to be generated without setting up 2FA is coercive and seems hard to justify, and it is plausible that it is being used to push people into attaching their phone numbers to their accounts. If I recall right, the current language for the setup process skews heavily toward phone numbers and does not do a good job of highlighting other (more privacy oriented) alternatives (as may be evidenced at least in the case of OP).

Re: Google's most ridiculous trick to force users into adding phone number

#90

Google is no saint, but there's absolutely no reason to ascribe ill intent to collecting phone numbers of 2FA setup. The reason is simple: Google has billions of users, and at any given time, a lot of them break their devices and lose access to 2FA credentials. Phone numbers, despite all their flaws, are still the most reliable long-term and mostly-immutable attributes which can service as a proxy for identity which…

This is an explanation for why Google might ask for phone numbers. This is not an explanation for why Google might require phone numbers. The only valid reasons for the latter are (1) to collect your PII and/or (2) because they think that they know better than you and they're going to force you to do a thing because they think it's in your best interests - in other words, a tyrant ruling over a techno-feudalistic soc…

> a tyrant ruling over a techno-feudalistic society

It's an email app. There are many other options.

Post reply on HN