Hacker News new | ask | show | jobs
by j4tech 1506 days ago
I totally agree with you. That was a mistake on my part . I had my number on the account a few months back.But my thinking was similar to what @orblivion posted below

"Because I've been warned by security conscious people never to use phone number as a 2FA because it's so insecure, and using it as a recovery option seems to create an even weaker link.". I happened to read so many articles in the recent past of SIM Swapping, that I was afraid to use my cellphone number as 2FA and removed it from my gmail account. What with Google being evil and all

1 comments

> Because I've been warned by security conscious people never to use phone number

Sadly you read only one part of the warning from security conscious people. The main part is to get U2F/FIDO key or use QR-code/authenticator. The same security conscious people use Fdroid/AndOTP where you can export all your 2FA codes.

There NO reason to say if I shatter my phone. Yes, you can also print recovery codes and keep it at home.

We're not talking about 2FA, we're talking about account recovery. I do have my authenticator app set up. Can I use it to prove myself if Google thinks somebody stole my account?
Yes, I just tested it with one my accounts that has NO recovery email address/phone. ONLY U2F key.

Select forgot password; the it asks Insert U2F Key. Then recovered. Yes, it may be that if one loses U2F key in Metro it is dangerous but some risk is always there. (i.e) how many times have you lost your key in your life? If more than one per year then keep one U2F at work and one at home.

Cool I'll look into it, thank you.