I just made a new Google account a couple hours ago, and it definitely looks like the preferred mechanism.
- There's one stage in the signup flow you can't bypass without SMS (granted, it doesn't automatically save that number to the account if you opt out, so that's nice).
- When setting up 2FA you're given giant messaging encouraging you to use a phone number. There's tiny text for other 2FA options.
- Those other 2FA options don't actually include TOTP. To enable TOTP you have to enable a "primary" 2FA solution (SMS, hardware key, or push notification), then enable a "secondary" 2FA solution (which can include TOTP), and if you're concerned about the shitty security SMS provides you then need to remove that as a 2FA option.
Edit: Mind you, it's probably reasonable given the state of the rest of their ecosystem to not have TOTP as the 2FA for your Google account (like if you have a chicken and egg problem trying to get into an android device with a TOTP app), but TOTP doesn't seem to be anywhere near as preferred as SMS.
That, and they do support hardware tokens out of the box (even if the UI doesn't make that super clear), so that's a step in the right direction.
But if you break or lose your cell phone you can just get a new one, and you have access to your 2FA token again immediately. It's much easier for people to work with. Yes it's less secure technically, but that sacrifice is worth it for a lot of people.
However you can lose control of your SMS phone number any number of ways that are beyond your control.
It's frustrating that so many providers push SMS as the only 2FA, when there are so many problems with it, and TOTP is provably better, privacy preserving, and much easier to work with.
I think there is too much emphasis on catering to the lowest denominator to the point of sacrificing privacy and autonomy , rather than raising awareness and education.
This seems like it would depend heavily on your threat model, especially keeping in mind that we're talking about second factors here.
For example, one threat is that bad guys gain access to the authentication data of the Relying Party. For example, maybe they find the daily backups are in backups.tgz on the web server for convenient downloading. Or maybe you never changed the password on the MySQL server. This is of course one way bad guys might have everybody's passwords, the first factor...
For TOTP the stored credentials include a "seed" value used to generate those six digit codes, and so by the relying party to confirm your code is correct. So for that credential access threat, the bad guys also have your TOTP codes and you're no better off with TOTP.
Whereas for SMS the stored credentials just include a phone number to send the one use codes to, bad guys having that isn't great news necessarily, but it doesn't actually give them the codes. Even if the one-use codes are stored in the same place as permanent credentials (which they may not be) and thus accessible to bad guys, the bad guys can't necessarily arrange to see them before you use them, and in any case can't arrange for you not to wonder why you're getting all these one-use SMS codes suddenly.
In contrast notably Security Keys don't end up with the Relying Party having any secrets at all, and so bad guys do not learn how to impersonate your users even if they somehow have access to the same means you use to authenticate those users.
https://en.wikipedia.org/wiki/HMAC-based_One-Time_Password
https://en.wikipedia.org/wiki/Time-based_One-Time_Password
Implementations vary, but TOTP was developed on top of HOTP and presents a standardized method to expire OTP codes.
However, I think you do have a point. The attacks that rely on intercepting SMS messages are cumbersome and are really feasible only for high value targets.
[1] https://www.androidpolice.com/2020/05/07/google-authenticato...
Depends on your definition of cumbersome, but it can be done fairly trivially[1] if you know what you’re doing.
[1] https://www.vice.com/en/article/y3g8wb/hacker-got-my-texts-1...
Which impedes the ability to sign up if one does not own a smartphone. I’m sure many people who are unhoused and rely on dumb phones need access to email to apply for jobs. Granted, I’m selecting a niche of a niche, but it’s a prime example of how badly the system is stacked against people trying to claw their way out of poverty.
2) Maybe pre-paid plans are contract based.
You used to be able to make gmail accounts without a phone by using an Android TV device. I wonder if that still works.
I'm not sure if it's still that way, but when I setup 2FA I could not directly setup non phone/sms 2FA (e.g. Yubikey, non google authenticator apps).
Worse even through I then explicitly disabled phone/sms based 2FA google at some point just switched it back one.
Worse there had been multiple times where having the 2nd factor but not the first (password) was enough to combine it with social engineering to completely take over an account. Some security researcher go hacked by this. Again I'm not sure it's still that way, but I don't trust Google anymore to not accidentally but a 2FA related vulnerability which makes the account less secure into their authentication flow. They either don't care (likely) or don't have the competency to handle this (unlikely). Well it's one of the reasons I'm slowly moving away from Google.
It increases the risk that a ban on an account will bring all of them down since you link them with same phone number identity.
First, I need to register a phone number as 2FA. Only then can I choose an alternate method, get codes, and have to select Google Authenticator to use my Open Source authenticator, Aegis.
Does not say Google Auth or any TOTP; specifically only says Google Auth. I was worried Aegis would not work until I tried it.
Why not show choices on the sign up screen? Why do I need to register a phone number first? It is very insecure in the USA. Data collection? Hold out from when a phone number was the only real 2FA and a TOTP was under additional options? If the latter, that needs to change if 2FA is going to be mandatory.
It's an anti spam/anti abuse feature. Getting access to new phone numbers that aren't recognized as virtual is pretty hard.
But the original blog post was so opaque that I completely misunderstood what they were going to do until pointed out in this article. It's bizarre how badly written some Google blog posts are these days.
As an aside, this is the second comment, now, that is confusing general 2FA with SMS-based 2FA specifically. Given the audience of HN this is honestly surprising to me and makes me wonder how common this confusion is.
That alone makes me glad Google is doing this as maybe it'll drive more folks to be educated about 2FA.
TOTP is only allowed as an "additional" means of 2fa and to enable it you already need to have the Google Android promt authentication/phone? 2fa configured (Maybe not exactly like that, but basically you cant just add TOTP without having something worse already added).
What I don't remember is whether or not I had SMS 2fa before and removed it, or never had it at all.
sucks to hear that you can't set it up that way initially anymore, if that's the case.
I just checked because I thought I was crazy: my account has SMS-based 2FA specifically disabled. The only enabled options are the Android prompt, Google Authenticator, and a set of backup codes.
For Google? They get to clean up (only keep "real" users) and reduce datacenter costs.
Once you've done that, you can remove SMS as 2FA. At least you could several years ago when I did it this.
I could not remove SMS first, I had to have 3 methods and then I was able to remove it.
The whole work/personal line is blurring more and more and our devices and thought patterns have not kept up with this. You could probably write one of those 'Things programmers assume about online identity' articles by now.
If you have a Google account for work you also have a work issued computer at minimum, so install a TOTP authenticator there.
If you also have a work issued phone it's a total non-issue as you can use that for 2FA.
If you access your work Google account from a personal device in circumstances where you don't have access to work equipment, then install an authenticator there.
I have a Google account for work. I don't have a work issued computer.
I think you're assuming too much about how other people might work.
I agree there are enough options that it shouldn't really be a big problem, but it's not surprising that not everyone are aware of the options.
Which must mean you're using personal equipment and you're not doing what the previous person was talking about, which was:
> It is very common to arrange your life so that you are able to 'hand in' all work devices and walk away.
Context matters. I was arguing a specific point based on a scenario the previous individual was posing. That scenario apparently doesn't apply to you, in which case, go argue with that person, because it wasn't my claim.
Now, if we want to talk about your specific circumstance, if you're using personal equipment to access a work account, stick a TOTP authenticator on your personal device.
I honestly don't understand what's confusing about this.
> I honestly don't understand what's confusing about this.
I didn't argue it was confusing. I argued against your assumption. And there's no need to use that tone - it comes across as aggressive and condescending. EDIT: I note this is not your only comment in this thread that comes across this way. Looking at your comment history suggests you're just direct, so I'll assume you don't mean anything by it, but it rarely goes over well here.
In my current position I can be called up for an emergency at any time. I'm not going to cart my desktop or laptop around on my day off, but carrying a phone for use with any reasonably secure machine I can find is a good solution.
People with responsibility for operations systems will find themselves in this kind of situation somewhat regularly. These are also the people most likely to seperate work and personal devices due to usage policies or risk profiles.
Edit: If you already have two phones due to your work life separation, then 2FA isn't really causing you to get a second phone is it?
https://www.twilio.com/legal/privacy/authy
The only privacy friendly method is no 2FA, just long secure passwords. Which is why 2FA is pushed so hard ...
This is absolutely ridiculous and so clearly false I can't help but wonder if it's intentional misinformation.
There are numerous open source TOTP authenticators for both the desktop and mobile that require absolutely no data to be stored in the cloud or shared with third parties.
I myself use KeepassXC and Keepass2Android.
If I was really paranoid I'd keep the TOTP database on a separate device but, frankly, I don't anticipate being the target of a motivated attacker so that's more than I feel is necessary given the threat models I'm concerned about, those being untargeted hacks (service breaches, driveby attacks, etc) and social engineering.
If you don't want to use Authy then use something else that doesn't backup the 2FA codes for you. But don't say 2FA is inherently a privacy concern. It isn't.