You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository has been archived by the owner on Nov 25, 2020. It is now read-only.
Basically, some services (namely Google) allows you to setup account recovery via phone number. This recovery option is NOT SMS-based 2FA. Enabling phone-based account recovery can circumvent the non-SMS-based 2FA that a user may have on their account.
EXPLICIT STEP TO ENSURE THAT GOOGLE USER DOESN'T HAVE SMS-BASED ACCOUNT RECOVERY:
I was originally turned onto this issue via zooko on twitter:
https://twitter.com/zooko/status/1138907707346264065
Basically, some services (namely Google) allows you to setup account recovery via phone number. This recovery option is NOT SMS-based 2FA. Enabling phone-based account recovery can circumvent the non-SMS-based 2FA that a user may have on their account.
EXPLICIT STEP TO ENSURE THAT GOOGLE USER DOESN'T HAVE SMS-BASED ACCOUNT RECOVERY:
When disabled, the section should look something like this:
EDIT: this might be good near the "Set up a mobile carrier PIN" section.
The text was updated successfully, but these errors were encountered: