This is awful from Google. They pretend this is for security when in fact it is a data grab.
@ericsfeed unfortunately it’s also the form of 2fa the general public rely on. SMS ain’t great but I’d rather have this in place than nothing. If you are creating a Google account, they will have access to a ton of metadata from the device your using anyhow, including phone number, location, device type, browser etc…
@cienmilojos this would be legit if the sms account was on file. Prompting for the phone number and then sending a code to that same number does not implement any kind of security.
@ericsfeed OK, yes that doesn't sound like the correct way to go about doing that.