Hacker News new | ask | show | jobs
by nullc 301 days ago
> Activate Google’s Advanced Protection Program

I'm dubious. This requires you give google a phone number. Almost universally if you give a company a phone number there is eventually an avenue for an attacker to convince the company to give them control of the account by demonstrating control of the number (which they've sim swapped or otherwise hijacked).

Even if at the moment there is no avenue to exploit google this way (also doubtful), all it takes is some new product (like workspaces) that has a different security understanding or new bugs to open a vector.

1 comments

A phone number is optional if you give a recovery email. Create an iCloud account you don't use for any other reason and don't share it with anyone.
Nope. Doesn't work. Insists on adding a recovery phone number.
What if you enroll two security keys?