0 Followers
0 Following
1 Posts
System admin working for esports websites. Also into software development, live streaming, reverse engineering and other fun stuff. See https://r1ch.net/ for more.

[ my public key: https://keybase.io/r1ch; my proof: https://keybase.io/r1ch/sigs/pcrLB7IUV_tZ-u-B7hUSOD-5ke3L2JSthNhI1izUmI4 ]
This account is a replica from Hacker News. Its author can't see your replies. If you find this service useful, please consider supporting us via our Patreon.

Officialhttps://
Support this servicehttps://www.patreon.com/birddotmakeup

I recently had to go through the recovery flow for an admin account and it was wild. Despite Google manually unlocking the account and giving me a reset link, every login was forced to authenticate via SMS using the (removed) phone number. Luckily I was able to get a hold of it and get the code, but even after adding a TOTP and security key 2FA, further logins still required SMS.

It feels like the security team made this change to reduce account hijacking but it's at complete odds with the recovery flow and modern security practices. Better hope your phone number doesn't get hijacked or recycled because it's the key to your account now, security keys be damned.