15

TL;DR: Google asked me to PROVIDE a phone number to verify connection from a new device, on the said device.

Yesterdayto log into my work Google account from my personal laptop to check emails, calendars update and so on. I opened up a private navigation window, went to Google sign-in page, entered my credentials, all is well.

Google then decided to "verify it's me" and prompted me to PROVIDE a phone number (work account without work phone means no phone number set up) so that they can send a verification code to the number I just provided to make sure the connection is legit.

Didn't want to do that, clicked "use another method" and got asked to fill the last password I remember, which would be my current password thanks to my trusty password manager. After submitting, I'm prompted with an error saying I have to contact my admin to reset my password because they can't log me in with my CURRENT password.

I ain't gonna do that, so went back to login page, provided my phone number, got the code, filled in the code, next thing I know I'm browsing through my emails.

What the duck? Could have been anybody giving any phone number. So much for extra security.

Also don't care that they have my phone number, the issue is more about the way used to obtain it: locking me out of my account and having no other way of logging in.

Comments
  • 3
    If you are sure that your phone number wasn't known in any way then you should reach out to Google really quick because it would be quite a big security issue.
  • 3
    They are just whores for your phone number at any cost
  • 2
    @Traser same happened to me. I gave them my burner number. Nobody knows that number besides me. They accepted it.
  • 1
    @Traser I can't be sure since I added the account to my Android phone at some point. But if they had my number already, why would they ask me to provide it again?
  • 3
    I think the point of this kind of phone verification isn't to prove your identity, but more meant to stop people from easily creating tons of fake accounts since unique phone numbers are reasonably difficult to come by.
  • 1
    It is probably a company policy, check with your admin.
    You can setup 2 step login instead of with a phone number.. if you admin wants.

    This is a serios privacy and security issue that you should raise to the dickhead admin.
Add Comment