Google is going to turn on 2FA by default
arstechnica.com
arstechnica.com
Beware if they claim they don't store your phone number. It's highly likely they store a hash of it for tracking purposes, and proceed to use child-like logic to claim they didn't break any law in doing so.
Furthermore, data brokers use the same hashing algorithm [1] to connect disparate/separate entities, such as your bank, insurance company, fast food chain, etc, basically, any entity you've shared your phone number/email with, in order to gather data on you behind the scenes. How did that happen, you ask? "Out of sight, out of mind."
Google could restrict non-2FA accounts. That way, users could still access their private collection of playlists, but maybe they're no longer able to make comments.
Google and others should offer a standard palette of 2FA options, where the risk factors are left to the users. Let them choose between verified email, some or other TOTP, but try to avoid scavenging private phone numbers, you know, the highest value, globally unique identifier, ooooh.
[1] https://twitter.com/WolfieChristl/status/1288229191759081472
* Prompts. (Show a notification on a device)
* Phone Txt or voice
* Backup codes
* Authenticator App (ie TOTP)
* Security Key: Yubikey and the like. (You can use some Android phones as a Bluetooth security key)
I'd say google has more options than anyone else right now.
A few months back I finally enabled 2FA on one of my accounts, I wanted to use totp and that option was completely unavailable until I enabled SMS 2FA.
You can argue that they shouldn't have made that mistake, and I'd agree, but stupidity is always more likely than malice.
It's interesting how the supposedly smartest companies of the world are so regularly so stupid in such consistent ways.
They're never stupid in a "oh no we deleted all your personal information from our system and now can't track you anymore" way, weirdly.
More generally, remember that you could be one of those megacorp employees one day, and you might build a 2fa system which logged to a particular place.
Later (remember the company is growing for 50% for many years) some new person sees the phone numbers and doesn't realise their provenance (very likely culturally at a place like FB, where things are default open) someone else finds the phone numbers and uses them to send marketing messages.
Like, that's what happened (most likely) but it amazes me that people will always want understanding for their own mistakes, but regularly disclaim that others shouldn't have done it, or made a mistake maliciously.
To be clear, I have no special insight here, but I think that assuming everything is malice and pre-planned is a less fruitful headspace to inhabit than realising that everyone is human, all companies make mistakes and that's a good prior.
To be even clearer, FB should have made this bug impossible (and I'm sure they have now), but given the amount of mistakes I've made I hesitate to cast the first (or indeed one of the last I suppose) stone.
And what happens if it's revealed? How large are fines, how long the prison time?
Or just keep a hash of the number as GP described.
My guess is, if they aren't nagging you about verification by phone number, you've likely provided them with your number at least once in the past.
On a related note, there's been a push for supporting the Payment Services Directive (PSD2), which requires strong customer authentication (SCA) in most cases, which implies 2FA.
Try it with a VPN or anything from a datacenter IP or any other public place and it's a no go.
They already have Google Authenticator. (Although authenticator plus is better imo) and they use your email address for that.
Using access to specific phonenumber as second factor is not too good security wise, but there’s no perfect options. I’d say managing 2FA properly is hard even for IT pros, let alone regular people. Like how many store the backup codes offsite, regularly test backup Ubikeys etc.
I tried to contact them from the email that used to be the 2FA, but no one could help me. It was a sad and eye-opening experience as I could have lost google domains and more.
Took about 3-5 days once I sent in the documents.
Is the process repeatable?
After that I activated the 2FA using authenticator... But using Authy, and has worked like a charm
www.google.com/signin/recovery
And give it a try instead to recover your account
There is a chance it might work
Thanks a lot !
I just made a new Google account a couple hours ago, and it definitely looks like the preferred mechanism.
- There's one stage in the signup flow you can't bypass without SMS (granted, it doesn't automatically save that number to the account if you opt out, so that's nice).
- When setting up 2FA you're given giant messaging encouraging you to use a phone number. There's tiny text for other 2FA options.
- Those other 2FA options don't actually include TOTP. To enable TOTP you have to enable a "primary" 2FA solution (SMS, hardware key, or push notification), then enable a "secondary" 2FA solution (which can include TOTP), and if you're concerned about the shitty security SMS provides you then need to remove that as a 2FA option.
Edit: Mind you, it's probably reasonable given the state of the rest of their ecosystem to not have TOTP as the 2FA for your Google account (like if you have a chicken and egg problem trying to get into an android device with a TOTP app), but TOTP doesn't seem to be anywhere near as preferred as SMS.
That, and they do support hardware tokens out of the box (even if the UI doesn't make that super clear), so that's a step in the right direction.
But if you break or lose your cell phone you can just get a new one, and you have access to your 2FA token again immediately. It's much easier for people to work with. Yes it's less secure technically, but that sacrifice is worth it for a lot of people.
However you can lose control of your SMS phone number any number of ways that are beyond your control.
It's frustrating that so many providers push SMS as the only 2FA, when there are so many problems with it, and TOTP is provably better, privacy preserving, and much easier to work with.
I think there is too much emphasis on catering to the lowest denominator to the point of sacrificing privacy and autonomy , rather than raising awareness and education.
This seems like it would depend heavily on your threat model, especially keeping in mind that we're talking about second factors here.
For example, one threat is that bad guys gain access to the authentication data of the Relying Party. For example, maybe they find the daily backups are in backups.tgz on the web server for convenient downloading. Or maybe you never changed the password on the MySQL server. This is of course one way bad guys might have everybody's passwords, the first factor...
For TOTP the stored credentials include a "seed" value used to generate those six digit codes, and so by the relying party to confirm your code is correct. So for that credential access threat, the bad guys also have your TOTP codes and you're no better off with TOTP.
Whereas for SMS the stored credentials just include a phone number to send the one use codes to, bad guys having that isn't great news necessarily, but it doesn't actually give them the codes. Even if the one-use codes are stored in the same place as permanent credentials (which they may not be) and thus accessible to bad guys, the bad guys can't necessarily arrange to see them before you use them, and in any case can't arrange for you not to wonder why you're getting all these one-use SMS codes suddenly.
In contrast notably Security Keys don't end up with the Relying Party having any secrets at all, and so bad guys do not learn how to impersonate your users even if they somehow have access to the same means you use to authenticate those users.
https://en.wikipedia.org/wiki/HMAC-based_One-Time_Password
https://en.wikipedia.org/wiki/Time-based_One-Time_Password
Implementations vary, but TOTP was developed on top of HOTP and presents a standardized method to expire OTP codes.
Which impedes the ability to sign up if one does not own a smartphone. I’m sure many people who are unhoused and rely on dumb phones need access to email to apply for jobs. Granted, I’m selecting a niche of a niche, but it’s a prime example of how badly the system is stacked against people trying to claw their way out of poverty.
2) Maybe pre-paid plans are contract based.
You used to be able to make gmail accounts without a phone by using an Android TV device. I wonder if that still works.
However, I think you do have a point. The attacks that rely on intercepting SMS messages are cumbersome and are really feasible only for high value targets.
[1] https://www.androidpolice.com/2020/05/07/google-authenticato...
Depends on your definition of cumbersome, but it can be done fairly trivially[1] if you know what you’re doing.
[1] https://www.vice.com/en/article/y3g8wb/hacker-got-my-texts-1...
First, I need to register a phone number as 2FA. Only then can I choose an alternate method, get codes, and have to select Google Authenticator to use my Open Source authenticator, Aegis.
Does not say Google Auth or any TOTP; specifically only says Google Auth. I was worried Aegis would not work until I tried it.
Why not show choices on the sign up screen? Why do I need to register a phone number first? It is very insecure in the USA. Data collection? Hold out from when a phone number was the only real 2FA and a TOTP was under additional options? If the latter, that needs to change if 2FA is going to be mandatory.
It's an anti spam/anti abuse feature. Getting access to new phone numbers that aren't recognized as virtual is pretty hard.
It increases the risk that a ban on an account will bring all of them down since you link them with same phone number identity.
I'm not sure if it's still that way, but when I setup 2FA I could not directly setup non phone/sms 2FA (e.g. Yubikey, non google authenticator apps).
Worse even through I then explicitly disabled phone/sms based 2FA google at some point just switched it back one.
Worse there had been multiple times where having the 2nd factor but not the first (password) was enough to combine it with social engineering to completely take over an account. Some security researcher go hacked by this. Again I'm not sure it's still that way, but I don't trust Google anymore to not accidentally but a 2FA related vulnerability which makes the account less secure into their authentication flow. They either don't care (likely) or don't have the competency to handle this (unlikely). Well it's one of the reasons I'm slowly moving away from Google.
But the original blog post was so opaque that I completely misunderstood what they were going to do until pointed out in this article. It's bizarre how badly written some Google blog posts are these days.
As an aside, this is the second comment, now, that is confusing general 2FA with SMS-based 2FA specifically. Given the audience of HN this is honestly surprising to me and makes me wonder how common this confusion is.
That alone makes me glad Google is doing this as maybe it'll drive more folks to be educated about 2FA.
TOTP is only allowed as an "additional" means of 2fa and to enable it you already need to have the Google Android promt authentication/phone? 2fa configured (Maybe not exactly like that, but basically you cant just add TOTP without having something worse already added).
What I don't remember is whether or not I had SMS 2fa before and removed it, or never had it at all.
sucks to hear that you can't set it up that way initially anymore, if that's the case.
I just checked because I thought I was crazy: my account has SMS-based 2FA specifically disabled. The only enabled options are the Android prompt, Google Authenticator, and a set of backup codes.
For Google? They get to clean up (only keep "real" users) and reduce datacenter costs.
Once you've done that, you can remove SMS as 2FA. At least you could several years ago when I did it this.
I could not remove SMS first, I had to have 3 methods and then I was able to remove it.
Edit: If you already have two phones due to your work life separation, then 2FA isn't really causing you to get a second phone is it?
https://www.twilio.com/legal/privacy/authy
The only privacy friendly method is no 2FA, just long secure passwords. Which is why 2FA is pushed so hard ...
This is absolutely ridiculous and so clearly false I can't help but wonder if it's intentional misinformation.
There are numerous open source TOTP authenticators for both the desktop and mobile that require absolutely no data to be stored in the cloud or shared with third parties.
I myself use KeepassXC and Keepass2Android.
If I was really paranoid I'd keep the TOTP database on a separate device but, frankly, I don't anticipate being the target of a motivated attacker so that's more than I feel is necessary given the threat models I'm concerned about, those being untargeted hacks (service breaches, driveby attacks, etc) and social engineering.
If you don't want to use Authy then use something else that doesn't backup the 2FA codes for you. But don't say 2FA is inherently a privacy concern. It isn't.
The whole work/personal line is blurring more and more and our devices and thought patterns have not kept up with this. You could probably write one of those 'Things programmers assume about online identity' articles by now.
If you have a Google account for work you also have a work issued computer at minimum, so install a TOTP authenticator there.
If you also have a work issued phone it's a total non-issue as you can use that for 2FA.
If you access your work Google account from a personal device in circumstances where you don't have access to work equipment, then install an authenticator there.
I have a Google account for work. I don't have a work issued computer.
I think you're assuming too much about how other people might work.
I agree there are enough options that it shouldn't really be a big problem, but it's not surprising that not everyone are aware of the options.
Which must mean you're using personal equipment and you're not doing what the previous person was talking about, which was:
> It is very common to arrange your life so that you are able to 'hand in' all work devices and walk away.
Context matters. I was arguing a specific point based on a scenario the previous individual was posing. That scenario apparently doesn't apply to you, in which case, go argue with that person, because it wasn't my claim.
Now, if we want to talk about your specific circumstance, if you're using personal equipment to access a work account, stick a TOTP authenticator on your personal device.
I honestly don't understand what's confusing about this.
In my current position I can be called up for an emergency at any time. I'm not going to cart my desktop or laptop around on my day off, but carrying a phone for use with any reasonably secure machine I can find is a good solution.
People with responsibility for operations systems will find themselves in this kind of situation somewhat regularly. These are also the people most likely to seperate work and personal devices due to usage policies or risk profiles.
> I honestly don't understand what's confusing about this.
I didn't argue it was confusing. I argued against your assumption. And there's no need to use that tone - it comes across as aggressive and condescending. EDIT: I note this is not your only comment in this thread that comes across this way. Looking at your comment history suggests you're just direct, so I'll assume you don't mean anything by it, but it rarely goes over well here.
Wanted to check if I’m just dumb, and all recent answer point to the same issue: https://www.quora.com/Is-it-possible-to-use-Google-2-step-ve...
Either that answer is out of date or it's lacking nuance. I haven't done it in a while, but it may be that you need SMS 2FA initially, and then once you've added TOTP you can then remove SMS.
But SMS is absolutely not required and anyone who thinks it is and is avoiding 2FA for that reason needs to go take a second look at their security settings.
What I was pointing at is not that SMS is the only option but that the phone number + confirmation seems mandatory at least once.
This and your other reply in this part of the conversation are purely paranoid speculation.
Frankly, if you're this concerned about Google's nefarious intent, you should get off their platform. They probably already know a lot more about you than just some random phone number.
I deleted my account with Digital Ocean years ago, because I use NoScript and every time I went to a new page at DO, it required me to enable more 3rd-party domains. I switched to Vultr.com because they only use their domain for their web pages.
Recently I received an email from DO that my acct information may have been accessed by some hack. I replied to that email, requesting that they delete everything on their systems relating to me. They said I had to sign in and purge my account. I already did this, when I switched to Vultr.com. But I tried anyway. It wouldn't let me sign in (Duh! I already deleted the account), so won't let me purge my info. When I explained that DO would have to delete it, they never replied. They obviously still have my info or they couldn't have emailed me.
My level of trust that a company has actually deleted everything they say they are deleting is about zero. If it's to their advantage to keep it, they will.
Ever since I realized that the 1Password desktop/mobile app can save and sync your 2FA code generators onto all of your devices, as well as automatically fill them, I have been a happy 1Password user with possibly hundreds of active 2FA setups.
Even if I lose all of my devices, there is at least a clear way forward with my 1Password recovery kit. I don't need to save millions of emergency recovery codes. Still, the biggest point of convenience for me is being able to access the same 2FA codes from my laptop, phone or tablet despite only entering them once on desktop.
I feel like I'm advertising for 1Password right now, but honestly this is perhaps the most exciting thing that has happened in over a decade for my personal cyber security situation. I have been able to completely decouple my phone number from my 2FA in most instances.
I get that if your password manager is compromised, you've got bigger problems, but some account seeds for H/TOTP should stay out of it and on a paper or dedicated piece of hardware.
My 2c.
This covers destruction of phone, destruction of office, destruction of Yubikey, destruction of me.
I would like to use U2F, but some companies (looking at you AWS team) only allow 1 MFA method period. And that just doesn't work.
That doesn't seem like an objection to U2F (or its successor WebAuthn) but more a reason not to use it for AWS or perhaps, if you have an alternative that does offer decent authentication, not to use AWS at all.
In this particular topic for example, the failures of AWS are no reason to avoid using the Yubikey's safer FIDO/ FIDO2 mode for your Google account.
Ebay is the best need know usernames of other users who live in my old flat 10 years ago.
Try to login to PayPal,ebay, outlook gmail from mexico or Vietnam captcha every 10 minutes everywhere how this people can live like this
This article speculates a bit that:
> On Android, Google Prompt is a full-screen pop-up built into every device as part of Google Play Services, so that's easy. On iOS, Google Prompt requests for your account can be received by the Google Search app, the Gmail app, or the dedicated Google Smart Lock app. It sounds like everyone meeting these requirements will soon be enrolled in 2FA.
So assuming this is correct, if your parents don't have an Android phone attached to the account, and don't have an iPhone with those apps installed, then this won't affect them.
Of course, it'd be nice if Google was a little more clear on what they're doing, here...
I bought my mother a Yubikey a while ago and walked her through printing out backup codes (stored in a location I will remember even if she doesn’t) and registering it with her Chromebook. It’s on her keychain, but she won’t need to use it until she gets a new computer when the Chromebook dies.
The advantage of this is that her account can’t be broken into remotely, which would be catastrophic.
(Contrast with another relative that I think is on her third Google account.)
Consider a game, as an example. A stolen account can be used to play with cheats or to commit credit fraud / chargebacks, and the typical punishment of banning the account is no longer a deterrent. If there's an in-game player market or gifting system, items can even be transferred to otherwise legitimate accounts.
How is that hurting the company? It would mostly hurt me as the original account holder. Except for the cheating, but that can just be done with a newly created account as well, so the only thing the fraudster would gain is not having to create an account.
If you want to get ahead of this and save your accounts I've been using MS Authenticator for years now and am very happy with it.
So don't use SMS.
TOTP authenticators don't require any data to be transmitted at the time of authentication. They're set up with an initial shared secret (typically transmitted via QR code) at which point the codes are generated independently on the two devices.
This means the TOTP device doesn't even need to be connected to the internet. As long as you can get the TOTP seed onto the device (worst case: type it in), you can use that device for 2FA.
I could set up TOTP on my personal account today, again without linking it to a phone number, but I don't because TOTP is less safe than my Security Keys which are already enrolled.
to Google's credit you can at least opt out of that part. (don't know if this is a global thing)
myaccount.google.com/privacycheckup
If you don’t have 2FA enabled for your account, you are in the least secure position compared with enabling any 2FA method.
Either way, there’s no need to use SMS for 2FA with Google, they support many other forms of 2FA.
Real 2FA would (theoretically) never make your account less secure than 1FA, because even if the second factor has 0 security, it shouldn't decrease the security of the first factor.
However, it is true that this may not always be the case for imperfect implementations, like your example. I can aldo imagine that social engineering might have a higher succes ratio if the intruder can say "it really is me! I have the correct second factor, I just lost my first factor...".
What do you suppose happens when the hot guy in the club who bought them and all their friends a round of drinks says they can make a month's salary in ten minutes if they allow a few of his mates to skip that "annoying" ID check?
And I'm sure that afterwards, once the carrier figures out who was responsible, they'll get fired. But meanwhile your accounts were taken over and leveraged for some scam or (if you own "cool" things like a short Twitter handle or that rare drop in a video game) sold to the highest bidder.
at the end of the day someone is sitting at a computer and given an id-card from a stranger and clicking the "yes, i verified their id card".
Whereas, of course, the reason we're discussing SIM attacks isn't that some bad guys might use your monthly download credits, or make a phone call that you pay for (the phone company would of course undo these charges once it was apparent that their employee caused the problem) but instead that this can be leveraged to gain access to all sorts of accounts your phone company has no responsibility for whatsoever.
The security was totally appropriate for the scope in which it was intended to be used, but that doesn't make it magically appropriate for all possible scopes.
And not just non-tech savvy users neither.
Did not have access to associated phone number.
* gave correct password * gave correct secret question response * have access to backup email address
“Thank you for verifying that you have access to the backup email address.
We have been unable to verify your ownership of this account”
Are you serious?? Google must seriously want to tie everything to real world IDs.
After about 5 years of occasionally flunking the questionnaire to prove I was me, Google relented and allowed me to update my password via a code sent to my phone and another sent to the gmail account itself.
Which is to say that I was saved by a device that had access to my original gmail for five years without ever asking for the password. Which doesn't seem like an example of sterling security.
You probably know this already but if you're making the effort to do this you absolutely must purchase a domain name that you own, it's the only way to make sure you'll never have go through this process ever again.
Then, three months later, I visited, and suddenly they've let me in. This is extremely annoying.
Oh, and I was visiting using the same IP address!
Oh please no, no, no, no a million times. I shoudn't have to run Google services on my phone, I shoudn't need to have a phone, and my big heavy immobile desktop should BE a 2FA device of its own because it's much harder to steal. Don't make the use of a desktop require a phone.
Also, as the article already says, as does Google's announcement, this won't do anything at all if you don't have any suitable additional factors.
https://www.researchgate.net/publication/315541163_No_Digita...
It really opened my eyes that google was willing to hold my emails hostage. Google's roadblock was unrelated to security, because an attacker could provide a new phone number too.
I checked my account and I don't see any secret questions options.
This experience is what pushed me off Gmail.
I think it's obvious that Google is too big, but it's not like they can help it. Capitalism in the internet age requires constant growth if you want to maintain your company's value, which is a large part of why they can't turn people away from their service. The best they can do is require a phone number to sign up and limit the number of accounts a phone number can be associated with (which they already do).
Craigslist is doing fine with a small number of employees and no need to grow.