Hacker News new | ask | show | jobs
by wavelen 1345 days ago
afair you need to set up a phone number before you can choose to add another 2FA option (which is stupid imho)
2 comments

Even if this is the case, this isn't a problem for the poster. They have a phone number, it just changes frequently. They can sign up, enroll in a TOTP or U2F system, and then they are set.
Except if you're using e.g. Google Authenticator and you lose that phone, you've now lost your TOTPs. The most unhoused-friendly solution there would be to use something like Authy instead (which is another password to remember, but at least it makes it easy to recover your TOTP keys on a new device without needing the old one); next best would be to use something like andOTP which supports backups (but then you'd need someplace to store those backups, which introduces the same problems as safely keeping a phone on your person).
The context for this post is a person who moves between countries frequently and therefore gets new phone numbers. This person has consistent access to the same phone.
The context of the overall post is the posted Twitter thread, wherein the specific issue is the phone itself being lost/stolen.
It's not stupid - Google wants to track everyone everywhere and a phone number is a good way to link an account to a real world person.