I just made a new Google account a couple hours ago, and it definitely looks like the preferred mechanism.
- There's one stage in the signup flow you can't bypass without SMS (granted, it doesn't automatically save that number to the account if you opt out, so that's nice).
- When setting up 2FA you're given giant messaging encouraging you to use a phone number. There's tiny text for other 2FA options.
- Those other 2FA options don't actually include TOTP. To enable TOTP you have to enable a "primary" 2FA solution (SMS, hardware key, or push notification), then enable a "secondary" 2FA solution (which can include TOTP), and if you're concerned about the shitty security SMS provides you then need to remove that as a 2FA option.
Edit: Mind you, it's probably reasonable given the state of the rest of their ecosystem to not have TOTP as the 2FA for your Google account (like if you have a chicken and egg problem trying to get into an android device with a TOTP app), but TOTP doesn't seem to be anywhere near as preferred as SMS.
That, and they do support hardware tokens out of the box (even if the UI doesn't make that super clear), so that's a step in the right direction.
But if you break or lose your cell phone you can just get a new one, and you have access to your 2FA token again immediately. It's much easier for people to work with. Yes it's less secure technically, but that sacrifice is worth it for a lot of people.
However you can lose control of your SMS phone number any number of ways that are beyond your control.
It's frustrating that so many providers push SMS as the only 2FA, when there are so many problems with it, and TOTP is provably better, privacy preserving, and much easier to work with.
I think there is too much emphasis on catering to the lowest denominator to the point of sacrificing privacy and autonomy , rather than raising awareness and education.
This seems like it would depend heavily on your threat model, especially keeping in mind that we're talking about second factors here.
For example, one threat is that bad guys gain access to the authentication data of the Relying Party. For example, maybe they find the daily backups are in backups.tgz on the web server for convenient downloading. Or maybe you never changed the password on the MySQL server. This is of course one way bad guys might have everybody's passwords, the first factor...
For TOTP the stored credentials include a "seed" value used to generate those six digit codes, and so by the relying party to confirm your code is correct. So for that credential access threat, the bad guys also have your TOTP codes and you're no better off with TOTP.
Whereas for SMS the stored credentials just include a phone number to send the one use codes to, bad guys having that isn't great news necessarily, but it doesn't actually give them the codes. Even if the one-use codes are stored in the same place as permanent credentials (which they may not be) and thus accessible to bad guys, the bad guys can't necessarily arrange to see them before you use them, and in any case can't arrange for you not to wonder why you're getting all these one-use SMS codes suddenly.
In contrast notably Security Keys don't end up with the Relying Party having any secrets at all, and so bad guys do not learn how to impersonate your users even if they somehow have access to the same means you use to authenticate those users.
https://en.wikipedia.org/wiki/HMAC-based_One-Time_Password
https://en.wikipedia.org/wiki/Time-based_One-Time_Password
Implementations vary, but TOTP was developed on top of HOTP and presents a standardized method to expire OTP codes.
However, I think you do have a point. The attacks that rely on intercepting SMS messages are cumbersome and are really feasible only for high value targets.
[1] https://www.androidpolice.com/2020/05/07/google-authenticato...
Depends on your definition of cumbersome, but it can be done fairly trivially[1] if you know what you’re doing.
[1] https://www.vice.com/en/article/y3g8wb/hacker-got-my-texts-1...
Which impedes the ability to sign up if one does not own a smartphone. I’m sure many people who are unhoused and rely on dumb phones need access to email to apply for jobs. Granted, I’m selecting a niche of a niche, but it’s a prime example of how badly the system is stacked against people trying to claw their way out of poverty.
2) Maybe pre-paid plans are contract based.
You used to be able to make gmail accounts without a phone by using an Android TV device. I wonder if that still works.
First, I need to register a phone number as 2FA. Only then can I choose an alternate method, get codes, and have to select Google Authenticator to use my Open Source authenticator, Aegis.
Does not say Google Auth or any TOTP; specifically only says Google Auth. I was worried Aegis would not work until I tried it.
Why not show choices on the sign up screen? Why do I need to register a phone number first? It is very insecure in the USA. Data collection? Hold out from when a phone number was the only real 2FA and a TOTP was under additional options? If the latter, that needs to change if 2FA is going to be mandatory.
It's an anti spam/anti abuse feature. Getting access to new phone numbers that aren't recognized as virtual is pretty hard.
It increases the risk that a ban on an account will bring all of them down since you link them with same phone number identity.
I'm not sure if it's still that way, but when I setup 2FA I could not directly setup non phone/sms 2FA (e.g. Yubikey, non google authenticator apps).
Worse even through I then explicitly disabled phone/sms based 2FA google at some point just switched it back one.
Worse there had been multiple times where having the 2nd factor but not the first (password) was enough to combine it with social engineering to completely take over an account. Some security researcher go hacked by this. Again I'm not sure it's still that way, but I don't trust Google anymore to not accidentally but a 2FA related vulnerability which makes the account less secure into their authentication flow. They either don't care (likely) or don't have the competency to handle this (unlikely). Well it's one of the reasons I'm slowly moving away from Google.