Google has, in some cases, started requiring auth codes sent to specific devices, even if you're already using your own configured TOTP 2FA.
Google has, in some cases, started requiring auth codes sent to specific devices, even if you're already using your own configured TOTP 2FA.
This exact situation has been such a thorn in my side at my company lately. Does anyone know any way to disable this behavior, even just with Google Workspace accounts?
If I've agreed to use and keep track of a very small physical device to access my account, don't be going letting any ol' person who can access my phone number in there!
Had that happen to me, I was saved by still having the backup codes + having some unholy Tasker + Pebble automations that let me operate the phone without display - enough to launch AirDroid, use it as remote display/input to enable ADB over WiFi, and then finally use scrscpy over ADB as a remote display/input that doesn't blank out on security screens and in Google Authenticator. Only at this point I was able to transfer all the other TOTP entries in Authenticator to the new device.
Lesson learned: 2FA with TOTP is a responsibility to be taken seriously, despite what security professionals would make you believe.
All these claims and not a single screenshot of this scenario. Meanwhile I've been in 4 countries in 8 weeks and Google hasn't bothered me once beyond the normal "tap my yubikey on my keychain".