cross-posted from : https://lemmy.zip/post/71321898
Netzpoltik details that police are able to gain access in this way either through physical access to someone’s phone or by intercepting verification codes via a state-sanctioned phishing attack or intercepting SMS messages via telephone surveillance


I’ll never understand why people accept SMS 2FA as any kind of security. Might as well put it as an ad in a newspaper. 🤦🏻♂️
Because many services only have SMS as 2FA option. Especially government services.
Also it is impossible to use google without enabling the SMS 2FA option. No matter what, with only 2FA authenticator app or email, they will lock down the account by saying “unable to verify”.
You can remove SMS 2FA from a Google account if you have passkeys or hardware security keys registered
But with a always on VPN they constantly ask to verify our identity, even with passkey or phone number.
Even when I successfully verify my passkey, they will still sent a SMS code to my recovery number. It’s almost impossible to bypass that step and try another method button redirect again to the same phone verification page. If I didn’t give my number, then this message appears, “there is not enough information to prove this is your account. try again later.”
Maybe VPN is a factor that triggering their security system.
Does it also include TOTP 2FA?
Not sure. You need att least one form registrerad. I do recommend using multiple.
I never set a phone number on two of my google accounts and they still work fine. Those accounts are old. Google didn’t ask for a phone number to sign up back then.
I recall seeing something about them planning to get rid of SMS 2FA last year. It looks like it’s still an option though.
Watch out, if those accounts are ever “locked”, you will get permanently locked out of the accounts. Happened to me because a data breach revealed my email address and some idiot tried brute forcing my password. Didn’t work but it broke the account. Secondary recovery email address and correct password wasn’t good enough. Support basically told me to give up and make a new account (???).
I guess in this case they block the account if it has no 2FA set up. If the account has TOTP set up it may be enough to avoid being blocked, even under brute forcing and without phone number.
You can have a Google account without 2FA, but you need to create it using a factory-reset old Android phone (Android 8 or so).
Why are people even complaining about this then?!
Because it’s an obscure / niche / loophole way. Not sure if it works on later Android, for example. Or in all regions.