Hacker News new | ask | show | jobs
by TheDong 1513 days ago
From your perspective, you're looking at a change that impacted you.

From google's perspective, they're looking at a change which reduces phishing and scams by some small percent, and impacts a minuscule fraction of their users.

Abuse, scams, phishing, and forgotten passwords are all significant problems which phone numbers help with. I'd be willing to bet these changes end up having an on net positive impact for google's users.

How many phishers do you think will be stopped by removing an insecure login flow? How many people do you think want to use insecure apps, but don't have a phone number and refuse to login to their google account on their phone?

2 comments

> How many phishers do you think will be stopped by removing an insecure login flow? How many people do you think want to use insecure apps, but don't have a phone number and refuse to login to their google account on their phone?

I actually don't know. Do you have any numbers?

Phone number is ultimate crossplatform and cross account identifier, only minority uses burner numbers for this. So I doubt that the phishing is the main driving motivation here, instead it is using phone numbers for easier tracking.
Phone numbers are also the primary thing people keep in contact lists and are very reliable to infer social graphs by stealing people's contacts and connecting the dots server-side.