Hacker News new | past | comments | ask | show | jobs | submit login

Don't use Phone number based 2Factor or if you must use a number, keep it to an app (eg, Google Voice) and don't forward your Google Voice texts to your phone's number.

Basically, avoid using your carrier provided phone number for anything related to an account.




But Google Voice requires a Google account, and to create a Google account you need to provide a valid phone number. There are also a lot of service providers that don't allow you create an account without providing a valid phone number.

I wonder how high-profile politicians and celebrities deal with security issues like this? If this is really such an easy attack to pull off, what's stopping someone from shilling cryptocurrencies on celebrity social media accounts (again)?


I deleted the phone number from google account, just use 2FA from app. Now forgot password does not give extreme option of just sending a code to my phone.


How do you recover your account if you don't have the app?


I mean sending a code VIA SMS. I mean I deleted the phone number from my Google account. Now I have only Auth App, & Google App. The code & recovery options are 8 digit recovery phrase, Tap in Google App on other device. No reset code SMS.


You can have a backup of the private key written on a piece of paper.


You could remove recovery phone number from your Google account use a couple (main and backup) hardware tokens like Yubikey as 2FA.


Google Voice SMS might not be able to help since they are all in the same POTS ecosystem as well.


Google Voice is US-only.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: