Phone number has been used too many times
support.google.com
support.google.com
Now that months have passed and my jets have cooled, I would like to take a moment and speak directly to Google:
Thanks Google. You finally gave me the push I needed to pack my bags and leave. I've completely de-googled my life and encourage everyone to do the same. You're an evil company. Anything positive you may have contributed to society has been long eclipsed by the damage you've done in your quest to subjugate the web. In short; good riddance and get fucked.
I'm no lawyer and can't say whether Google complied in a minimal fashion or not. But maybe not. [Edit: Checkboxes are insufficient, apparently]
But apparently Google's knowing that you're a right-handed tae-kwon-do enthusiast that flies every month is not sufficient for them to maybe think you're not a minor.
FWIW, I'm always happy to give my dob to these websites. Its the epoch of course. Memorable for me and boring for them.
(as they should)
I rarely log in, and I wasn't using the Google account at the time the email was sent, nor do I ever use the attached YouTube account. The card was saved in Google Payments without my consent.
https://support.google.com/youtube/answer/10070779
Then there's also the question of creating a payment profile for the user without consent.
> If you enter your credit card info for age verification, Google will retain this data as necessary to meet legal and regulatory requirements.
https://support.google.com/accounts?p=age-verify
Meeting legal requirements is very different from saving your card in Google Payments, which then you can readily use to buy products in any Google service.
and verifying that your financial/documentation circumstances permit you to qualify for a credit card in the first place, too. Nice way to gatekeep out the "undesirable underprivileged" user base not worth marketing to...
It is incredibly unnerving to me.
By what source do Google claim to know my exact birth date?
The only way I can theoretically change this is if I "claim" this "knowledge panel" which involves sending more personal information to Google without guaranteeing anything.
This happened to a customer where their IT sysadmin got a prepaid phone and registered this as a recovery number in a critical system (read as: full control over infrastructure).
And yes, the company forgot to refill the SIM card only to realize a year later that some script kiddie got the phone number by accident and was curious enough to lookup where the number was being used. DNS entries and ASN entries were enough OSINT to form an attack strategy.
What you gonna do then? As it turns out, this was a shitstorm of problems to deal with through hours (probably days) of support hotline calls.
Remember folks: 2FA via SMS is useless. Avoid phone numbers like the plague, everywhere.
I use a GV number for 2FA over SMS as the last mile solution.
Even when I did get a "real phone number" (that concept irritates me to no end), one of these first required me to send a phone bill as a "proof of me owning that number" before they would let me set it for 2FA.
I guess that's just what happens when blending/confusing the three distinct concerns of spam/fraud protection, 2FA, and user identification (for inbound P2P payments) into a single identifier.
- I can own my email address; I cannot meaningfully own a phone number.
- Email is international. Phone numbers aren't. (Edit: Often, not all countries/dial codes are accepted by sign-up forms, and it's usually not feasible to keep a phone number when moving internationally.)
- Email works with or without a cell signal/via mobile data.
- Many email providers offer 2FA, and domain name port-out prevention seems relatively robust these days. SIM swaps and port-out attacks still seem way too easy to pull off.
Just don‘t also tangle it to my user ID and/or 2FA recovery.
They are a pretty decent identifier for users. Facebook demanded my phone number for "security" purposes then turned around and used it as a unique identifier to tie me to purchase records from various businesses (e.g. Ticketmaster - why am I not surprised?) that apparently have shady tracking/advertising deals with Facebook.
This sort of information misuse and tracking (not to mention spam) is precisely what "sign in with Apple" was supposed to fix in terms of e-mail addresses, but it's currently instantly neutralized by SMS "verification" since it's a huge pain to get a different phone number just to prevent Facebook from using it as a tracking identifier.
(I guess this reminds me why I have said "no" to multiple inquiries from Facebook. The thought of being told to implement a dark pattern as part of your job is extremely unpleasant. Facebook's confusing anti-privacy settings are another example.)
And it's not just Facebook. This is seeping into other completely unexpected applications; for example I bought a game controller whose driver software setup demanded a mobile number for "verification" purposes. No, just no.
I agree with the gist of your email, but what is this supposed to mean exactly? The whole world shares a single phone (number) system, right?
> An individual has a phone number
> Some people do not own phones, or do not wish to provide you with their telephone number when asked. Do not require a user to provide a phone number unless it is essential, and whenever possible try to provide a fallback to accommodate these users.
Source: https://github.com/google/libphonenumber/blob/master/FALSEHO...
I'm not sure how you get a number from Ma Bell anymore, and I'm not going to do it for Twitter.
FAANG isn't quite as bad as WeChat, but it's getting there.
You can get away with using the same number for about five accounts (at least this was my experience).
(Oh, and of course you can port your physical-at-the-time-of-registration phone number to VoIP, which I may or may not have done, and they don't go back in and check against the database. TOCTOU, a classic security vulnerability since approximately 1970.)
It grinds my gears because I have been a Nitro subscriber since it first became available, and they won't bend one millimeter for one of their first paying customers. I am looking forward to their death by greed.
Really the only place that gives me issues is Chase Bank.
The rep was able to white-list my number.
I hope it's not the case (and I am enjoying my alternate, non-google emails) - but it seems that "so goes Google, so goes the web" has happened often enough that I worry
If you ever want to get a feel for how truly not-free the Internet is, try browsing through a VPN for a few days. Lots of stuff doesn't load, period. And you'll get constant "we've detected suspicious behavior from your IP" warnings, followed by endless capchas.
Apple will accept a Google Voice number as a trusted phone number on your iCloud account, and it even works with their SMS 2FA, in the few places where they still support that.
The root of the problem seems to be that the POTS seems to demand a ridiculous level of trust of all participants, which does not scale beyond a handful of incumbent market participants.
I like being able to take my phone calls wherever I am, with or without cell signal. Don't blame the technology; blame the broken network.
I have never had this problem with PIA.
What exactly is the point of phone verification of the official answer is “lie to us about your identity”?
If this was about security, SMS-2FA would be laughed out the door.
Phone number is not about identity, but about reducing spam (they're also not at all tied to your identity, at least not unless you buy data from service providers). The point is that you need something that is very easy for your normal user to do, but very hard for bots - effectively, it's just a glorified captcha.
Often you're not applying these policies to everyone, but only to small sub-populations with a high density of abuse. E.g. if 1% of your accounts are created via VPNs + VOIP numbers, and 99% of those accounts are deemed to be abusive post facto, and you restrict VOIP numbers for just signups for VPNs, the absolute maximum reduction in legit signups is 0.01%. You don't even need to know how many of the legit users would find another way to create the account; you already have an upper bound that's within the guardrails.
Or you can look at what actually happens after you roll out the policy. If it really is watertight, abusers will move away quickly, and all you're left with are the legit users. If that number is low enough, you might even keep the rules in place indefinitely even though all the traffic that is remaining is expected to be FPs.
If those approaches sound dodgy, the default option is to run an A/B experiment. Ban VOIP numbers for the experiment group and allow them for the control group. Then simply look the number of newly created abusive accounts vs. accounts with legit interactions in the two groups.
(A lot of requires you to have a way of distinguishing between abusive and legit users post facto, but if you don't, it's too early to add this kind of restriction in the first place.)
Sure, because what's the chance the friend also has a Google account? And who doesn't have a personal landline, especially these days?
Sorry to be snarky, but responses to the point of "sorry that our systems are horrible, nothing we can do, here are a few hoops to jump through to possibly deal with it" just get me. It's not just in Googles power to change something, it's literally a problem created by Google.
Why anyone would volunteer to answer queries for free in this context is beyond me. What do they get out of it? A flashy hat to wear and a few trivial perks?
Respect to those trying to help out, but when a question like this is posed in the forum, I would only be interested in hearing the response of a salaried Google employee, not a volunteer.
It's even worse when the response offers trite, generic information that doesn't relate to the problem, regrettably a common occurrence on this type of forum.
Edit: Note, these remarks are not applicable to the commendable people providing support in FOSS projects, and in other non-commercial contexts.
Stack Overflow is a general Q&A site, not a support forum for a commercial product. The context is very different. Also, while I'm at it, it has its own flaws, but people providing trite and useless answers isn't one, they get downvoted to oblivion.
Even worse worse when the response is actively hostile. Previously discussed: <https://news.ycombinator.com/item?id=28216896>
Google, as a company, has still not figured out customer support. It is evident in their Google Suite products, GCP and Pixel phones.
Contrast with Apple, where I've gotten knowledgeable humans on the line within a minute or two, and scheduled a service appointment at a nearby store.
If Google wants its Pixels to be the iPhone of the Android world, then they should provide more than the bottom-of-the-barrel outsourced support they currently offer.
In general, Google's support is mostly nonexistent. There are harrowing stories of Pixel support, but I have not had them, so ehh.
On the other hand, I have had humorous kerfuffles with Dell in trying to stop them from sending me a replacement unit that turned out to be unnecessary (even though the support rep had issued a replacement ahead of arrival due to a report of damage by UPS). They said we'll ship you one, just let us know if the one that arrives is not damaged and we'll cancel it. Despite me doing that in triplicate they still sent it to me. And then after I spent a bunch more time getting support to understand this, I was able to ship it back via FedEx, and about a month later I got a notice that I never did... Again, was able to remedy this with a chat with support and sending over some proof, but it left much to be desired.
That said, Google has allowed me to use my Google Voice number for account verification for a very long time now. It probably helps that I added that number before I ported it over to Google Voice but it's nice not having accounts tied to phone bill.
Recently, a service has been established in some cities that allow a mobile number owner to delete the accounts related to the number at multiple services. [1]
1. https://www.ithome.com/0/600/098.htm (Chinese)
Which is perfectly reasonable to be fair. I fixed it by deleting some of the accounts.
If the authors problem is similar that would probably be the easy solution. If it’s because the author has “inherited” a phone number that has previously been used by other people to create Google accounts then I think the author is going to depend on this HN post catching enough traffic for real people at Google to care. Because I sure didn’t find any help through their support system back then, and simply fixed the issue as a “happy accident”.
so, how?
(disclaimer, work for Google but not on this)
Another reason why phone number login is a ridiculous idea. Now this user is locked out and has to contact the CEO of Google for support. (Since there is no Google customer support)
We haven't even gotten to talk about SIM swapping and SS7 attacks yet. [0] Complete hell-hole of account takeovers.
There are two scenarios:
1. The expected use-case: Create account(s), assign number for verification, verify, account active, number remains assigned to account(s)
2. The unexpected: Attempt to create account(s), assign number for verification, ignore or fail verification, no account created
If the attempted use of the number in (2) is counted and remembered then there's an anonymous potential DOS against any number
Phone number as unique person identifier is hugely problematic for a lot of reasons. I wonder how many accounts you could hack just by constantly acquiring new numbers in area codes where the supply is small and then trying to reset various things by phone number.
> if there's any.
Have support.
So I sense some of the anger is due to google's reputation in this regard.
1. I can associate a phone number/email to a bunch of online services, but to unbind any specific one, I need to visit that specific website to put a request.
2. Especially for recycled phone number: it is nearly impossible for the new owner to unbind and clean the connection made by previous owner.
3. Cancel the recurring payment on your card. You either go through the service provider or call your bank/credit card issuer. However, it is usually more complicated compared to the moment when you clicked yes button.
It is super easy to start a digital service, while the other way around is not easy, and more than usual, hard as hell.
I once asked "hey, I know you can ignore single email addresses but is there any general way to prevent people from sharing porn to my Google drive or having bots message me in the gmail chat widget, because the default is anyone can do this to me regardless of privacy settings."
It seemed ridiculous to me anyone could message me out of the blue or share porn with my drive that shows up (thumbnails and all) in "recent". Individually ignoring the thousands of spammers isn't a solution.
The response was something like: "You can ignore individual users by right clicking their username and hitting ignore!" Thread closed. I can only imagine the responder didn't even read my question or just didn't care and was trying to make some quota or something. It's pretty clear they really don't care about supporting their products at all, and you'd probably be better served talking to a wall.
Not your domain not your mail.
I'm trying, but I cannot escape.
It's pretty much what you might expect from a company that makes its money B2B rather than through pleasing consumers.
From a user standpoint, I know of no service that will perform ID verification for 'free' and certify that verification onto a third-party verification request. (Credit card verification, or mail-you-a-postcard verification, doesn't count, as there's no ID check.)
I believe this ends up having to be a government service, where the post office is obliged to certify third-party verification requests presented to it (for private parties, corporations, and/or government divisions), and this service is offered for free at personal-use volumes and for one postage stamp per request at for-profit volumes.
It's still possible a B-corp or non-profit could decide to offer this as a public service, but that would take a billion-dollar endowment and would duplicate the USPS frameworks already in place to check IDs and verify mailing addresses for Informed Delivery at every post office in the country, so I wouldn't bet on anyone taking on that cost without payment.
Or Apple FaceTime Attestation?
But luckily I could appeal the ban of my main (personal) account and the copy read something like:
We want you to keep communicating with Gmail, so you can appeal to get your account reinstated here using this form.
Turns out Google is human after-all, and I learned my lesson.For those wondering why I wanted so many Google accounts; well at the time Google+ was happening and I wanted to promote a bunch of SaaS products and side hustles. In truth, I wanted to spam G+ with links. But the takeaway from this is: Google does let you appeal and has your best interests at heart, despite any rogue/malicious intent.