Hacker News new | ask | show | jobs
by uup 1346 days ago
So use one of the other 2FA options.
3 comments

Not always a possibility. Many banks require phone number based 2FA, for example. And you're required to use it any time you want to make a transaction that exceeds some threshold.
We are talking about Google here, right?
(FWIW, my bank does not provide any other 2FA options.)
afair you need to set up a phone number before you can choose to add another 2FA option (which is stupid imho)
Even if this is the case, this isn't a problem for the poster. They have a phone number, it just changes frequently. They can sign up, enroll in a TOTP or U2F system, and then they are set.
Except if you're using e.g. Google Authenticator and you lose that phone, you've now lost your TOTPs. The most unhoused-friendly solution there would be to use something like Authy instead (which is another password to remember, but at least it makes it easy to recover your TOTP keys on a new device without needing the old one); next best would be to use something like andOTP which supports backups (but then you'd need someplace to store those backups, which introduces the same problems as safely keeping a phone on your person).
The context for this post is a person who moves between countries frequently and therefore gets new phone numbers. This person has consistent access to the same phone.
The context of the overall post is the posted Twitter thread, wherein the specific issue is the phone itself being lost/stolen.
It's not stupid - Google wants to track everyone everywhere and a phone number is a good way to link an account to a real world person.