log into Google
giant banner appears
"Hey, is this still your phone number? If it's not you better change it otherwise we can't recover the account!"
click 'no'
change it to a new one
done.
log into Google
giant banner appears
"Hey, is this still your phone number? If it's not you better change it otherwise we can't recover the account!"
click 'no'
change it to a new one
done.
If you miss that step, because you're in a hurry, your kid pressed the button while you looked away, or whatever, you shouldn't be immediately locked out of your whole life without recourse.
We allowed ourselves to be held hostages by these companies, but we should know better now.
If you're already logged into Chrome and logged into your phone, it might take a few years before you get to "many times"
Maybe the last time this banner appeared, they still had their number. Maybe things just co-coincided with the worst possible timing. Stuff like that can happen.
I'm really not comfortable calling them completely incompetent over this.
Also there have been reports of people getting locked out for no fault of their own as well. And those people too have no chance to do something about it.
But even if it is incompetence or gross negligence - as a software company, you'd still want people to be able to report that stuff happening, so that at least you get statistics that you can use to measure the effectiveness of any improvements you try to make.
If those problems occur so frequently that it's no longer financially feasible for you to actually look into them... then maybe there's some incompetence going on at your own side, right?
Also, Google doesn't always make it clear when something is being added as 2FA. E.g. if you log into an Android phone future logins will use it as 2FA.
Then, when trying to access my passwords stored on my google account (passwords.google.com) I was prompted with a message saying that there was suspicious activity on my account, and I needed to approve a pop up on this android phone. Google would not let me access the password manager until I could physically drive back to that phone to approve it. They refused to provide me with any alternative options despite having a yubikey and sms. Finally, I navigated to my inbox (everything else would load except for that password manager) and went into details at the bottom of the page, then forcibly signed out of that android phone. Bear in mind this was the same device that it refused to let me access the password manager on.
Anyway, after removing the device from my account it let me access passwords.google.com
You can't force people to be truthful online, just like you can't fill up every crack on the Earth with cement.
If I ask you to confirm you haven't changed your number and you outright lie then I'm sorry but it is what it is.
It is completely disingenuous to frame this as though Bob walked up to Alice after lunch and asked her "Has the phone number you used for authentication changed?" and she lied and said "No".
And it seems obvious that in most cases, users that lose access to 2FA methods are not asked "has your 2FA changed?" while they still have access to the account. It is far more likely that one day their cookies are reset or google decides it's time to reauthenticate and they realize that they changed their phone number when they switched phone plans a week ago, and they hadn't thought about the consequences.