Gmail prompt to provide phone number sounds like a threat

  • KevonLooney@lemm.ee
    link
    fedilink
    arrow-up
    32
    arrow-down
    20
    ·
    edit-2
    1 year ago

    No it doesn’t. It means that your email is encrypted and they don’t have a way to unlock it. If you don’t add recovery info or print out your unlock codes, you will lose access. Just like it says.

    2FA is more secure.

    • The Hobbyist@lemmy.zip
      link
      fedilink
      arrow-up
      36
      arrow-down
      3
      ·
      1 year ago

      What are you talking about? Google is not encrypting their emails, where did you get that info from?

      • nbailey@lemmy.ca
        link
        fedilink
        English
        arrow-up
        9
        arrow-down
        6
        ·
        1 year ago

        Yeah, this has nothing to do with encryption, it’s because they refuse to have a support division that would be able to get people back into their accounts.

        • stratoscaster@lemmy.zip
          link
          fedilink
          English
          arrow-up
          8
          arrow-down
          2
          ·
          1 year ago

          What? No, that’s the whole point of 2FA. There is literally no other way to verify authorization otherwise because it’s by-default incapable of verifying identity.

          Knowing the previous password doesn’t help because those are often found in password dumps.

          This is true of any email service.

          • Madlaine@feddit.de
            link
            fedilink
            arrow-up
            8
            arrow-down
            1
            ·
            1 year ago

            2FA is just a second password and has nothing to do with encryption. Can simply be removed.

            They could bypass this authentication without problems, if they want. I lost my phone and my google business account got restored regardless of 2FA. It’s just a button for the support. The problem is the identification, especially of private customers (dunno if they would even do that).

            Encryption passwords aren’t time-based either, they must be static.

    • pe1uca@lemmy.pe1uca.dev
      link
      fedilink
      arrow-up
      10
      arrow-down
      3
      ·
      1 year ago

      Is it really encrypted?

      I’m guessing it’s only for the account recovery to reset your password which should be hashed.

      • Blizzard@lemmy.zip
        link
        fedilink
        English
        arrow-up
        15
        ·
        1 year ago

        Is it really encrypted?

        Of course not, Google has full access to your e-mails and uses it the whole time.