Hacker News new | ask | show | jobs
by Daedren 1506 days ago
Google allows for various kinds of 2FA, not just SMS. You can use a hardware key or even Google apps installed on other trusted devices.
3 comments

Great, can I use a hardware key (or authenticator app, in my case) if I get locked out of my account like the person who posted this question? That's my point.

To be clear, 2FA != account recovery.

Not for all accounts. After several years, they started strongly recommending an SMS verification, then finally locked my account when I couldn't provide them one. [I have SMS turned off by my cellular provider] Every year or so I'll see if I can get back in. Sometimes I'm presented with a non-SMS option, but once I work through that, they go right back to insisting on SMS.

I only used that account for communicating with one friend, [our mail hosts were blocking each other in some kind of spam war tit-for-tat] now deceased, so it was no great loss to lose the account, but rather annoying that they pretend harvesting phone numbers is some type of "authentication."

But if you don’t remove your phone number then the insecure option is still present.