It gets really annoying when you want to sign into $service on those machines, but you need to use a magic link. Because the you need to login into your gmail, which requires an additional 2fa (and you can’t receive sms in a building that has 6 stories but no femto cells).
Unfortunately google requires either their app or SMS. They dropped pure totp for some reason.
Awful experience.
Gmail TOTP still works fine?
I use TOTP with my Google Account all the time. If you have a phone registered with that Google Account it will default to the push notification system first (it might even be possible to make this no longer the default, I'm not sure), but you can always click the button to switch to alternative 2FA options.
Google plainly dropped totp wherever possible in order to confirm everyone's identity.
Totp was an open standard that didn't help them spy on anyone, and they regret releasing it bigtime.
You have to add a phone number, turn that on for 2fa.
Then you can add TOTP.
Then you can disable SMS.
SMS will still work for at least a week because fuck you.
There are alternatives to this, such as typing a code into the login prompt instead of following a link (which will be submitting that code). This does limit the size of token that can be used because it needs to not be too inconvenient for the user to type, but if the code's validity is sufficiently short-lived, and properly unguessable, this can be done without compromising security any more than it already is by involving SMTP in the process.
Of course the other problem with email-only password resets is that users often receive email on the same device they are trying to authenticate – so if someone has left a machine unlocked with their mail account logged in, an attacker can gain access to any site/app that uses this password reset mechanism. One of the reasons that email and SMS are not great choices for a second factor, and even less good choices for what is sometimes effectively the only factor.
I actually occasionally fantasize about implementing a mechanism that I could use from my desktop (where my password manager is) to send passwords as needed (e.g. one at a time) to my devices (I really like not worrying about syncing whole vaults). Encrypt the password using an epehemeral key (gets deleted after 60 seconds, for example) on the transfer service and a local key derived from a random six digit number. Display the number, send a url to the device, and anyone hitting that URL has 60 seconds to enter the six digit code and it decrypts the password and drops it on the device clipboard. This is about 1000 times better (and over-engineered, naturally) than my current practice of "paste it in a slack message to myself."