Hacker News new | ask | show | jobs
by blablabla123 2662 days ago
> but apparently nothing matters except your phone number when it comes to recovering your account.

Kind of legit to be honest. Anything else would make it far too easy to recover accounts. Also Gmail is far too large to have a customer care that could also do things like passport verification or so.

Having said that, Protonmail has no phone number recovery. That's kind of bad. You can enter an old E-Mail address there though but it would be so much better to link this with a phone number. If you loose your sim card, you can always get a new one from the phone company with your passport.

2 comments

> Kind of legit to be honest. Anything else would make it far too easy to recover accounts. Also Gmail is far too large to have a customer care that could also do things like passport verification or so.

Why is being able to recover accounts easily a bad thing when you, and only you have or should have access to, say, the password?

> Protonmail has no phone number recovery. That's kind of bad

I do not use it, so it is fine by me.

> If you loose your sim card, you can always get a new one from the phone company with your passport.

Not necessarily. It is more and more difficult to get a new one, and there are prerequisites that one may not meet, or they decide they do not want to do business with you, or your social credit is too low, etc.

The differences are: one is given to you by a third party, and the other one is made up by you.

I would like to be able to opt out of it, e.g. phone number should not be required.

>Protonmail has no phone number recovery. That's kind of bad. You can enter an old E-Mail address there though but it would be so much better to link this with a phone number. If you loose your sim card, you can always get a new one from the phone company with your passport.

Considering how many high profile bitcoin thefts occured using hijacked phone numbers, it's probably better not to have that as a reset method.

But this should be up to the user. I mean if your 1 million BTC account is protected through a phone number, someone might want to still do it that way.

Most users don't even have Bitcoin but normal bank account which are oftentimes protected by different second factors. It would be nice if they would provide different options. For me it would suck if someone hacked my E-Mail but I could reclaim it quickly and the damage would be very limited.