Gmail registration now requires scanning a QR code and sending a text message

(discuss.privacyguides.net)

110 points | by negura 7 hours ago ago

53 comments

  • dvh 2 hours ago

    Any Gmail person can tell me why Gmail is tolerating Gmail phishing emails that use Google's own services (e.g. https://storage.googleapis.com/savelinge/... ?

    More info here: https://news.ycombinator.com/item?id=46665414

    • torben-friis 2 hours ago

      Spam is getting horrible lately. I get all sorts of new techniques including:

      - using legitimate sites to bypass filters, like sending you a bill through a legitimate bill-creation site

      - pretending to be a tracking service for something you supposedly ordered, then over the course of days pretending the package got lost on the way and offering a discount code for the 'purchased' amount, expecting you to use it on their phising site.

      Gmail not only fails at spam classification, they classify these messages as important and nag you with first priority notifications and summaries.

      • traviswingo 27 minutes ago

        I can’t prove it, but it feels like the world recently decided that spamming/scamming is acceptable, so the number of spammers/scammers has increased dramatically.

        The number of spam calls, texts, emails, iCloud account unlock requests, etc I’ve received in the last year is insane.

        • abirch 9 minutes ago

          It's AI that's doing a lot of it. For a lot of spam, scammers would want to exclude anyone who may not fall for the scam due to the costs associated with dealing with people who won't pay you. Now that AI decreases the need for a human scammer to scam, expect them to start to widen their scam nets.

    • Aboutplants 7 minutes ago

      It follows the same logic as physical junk mail. We accept the fact that we will receive junk mailers in our physical mailbox and just toss them out.

    • dewey 2 hours ago

      The same reason spam filtering is hard. It's not possible to catch every misuse of the service without too many false positives.

      • dvh 2 hours ago

        The same 5 urls has been used for 3 months

        • dewey 2 hours ago

          That doesn't really change the fact that it's hard. Do you know how many full movies are on YouTube that infringe on copyright? How many pirated streams are hosted on S3? How many piracy sites are behind Cloudflare. It's just very hard to police at scale and if something is flying below the radar it will be there for a while. They probably spread out their assets over many accounts, or even use misconfigured buckets with write permissions to drop some files in there.

          • BLKNSLVR 4 minutes ago

            Google's inability to scale their services should be a regulatory issue.

            If their platforms (Gmail, YouTube, DoubleClick) are being used to launch scams, they're failing at scale and governments are failing at legislating / regulating.

            All this ID and surveillance and privacy invasion and metadata retention and yet all these scams only seen to grow. It never seems to end up protecting anyone deserving of protection.

            I wonder what it's all been in aid of...

          • spaqin an hour ago

            I kinda lost the plot here - what does piracy have to do with spam and phishing?

            • em-bee an hour ago

              both deal with distinguishing legitimate vs illegitimate content.

          • unholiness 2 hours ago
            • hydrogen7800 an hour ago

              "It's so easy when you don't know how". I'm not sure if this phrase is in common use at all, or if I just misheard it once and attributed it to mean that when the details of a problem aren't obvious, its easy to conclude the solution is simple. "Why don't they just do ___?"

              • irishcoffee 38 minutes ago

                At the companies I've worked at, I refer to this as the "well, can't you just...?"

                Yeah, I can "just" after I "just" do A, and B, and C, and D, and E, and F, and G.

                Drives me batty on top of being insulting. "Surely you realize I thought about that weeks ago, and if it were that simple, we wouldn't be having this conversation."

                But hey, I get paid every 2 weeks.

      • cyanydeez 2 hours ago

        Ok, it's even harder when you do not care because they people are either freeloaders or locked into your solution because it's a customized mess.

  • Aurornis 2 hours ago

    > Supposedly, using the QR code on the smartphone triggers an SMS sent from your phone to Google in order to verify your phone number.

    Does anyone have a better source of information than this one forum comment from someone who thinks scanning a QR code is enough to get your phone to send a text message?

    EDIT: It’s just an SMS URI. It doesn’t automatically send anything, just opens a text message for you to send.

    This is just the old phone number verification with a QR code convenience method.

    • gruez an hour ago
    • mghackerlady an hour ago

      What happens when your phone can't do that? I use a flip phone. It can't scan QR codes despite having a camera

      • user_7832 15 minutes ago

        Technically if you can copy paste the qr code into any qr reader website and manually do it, I think it's possible? Assuming it doesn't change the code very rapidly every few seconds.

      • Aurornis 23 minutes ago

        Apparently it’s just an SMS URI.

        It’s not something specific to a phone. It’s just a convenient method to enter your phone number.

        • croes 17 minutes ago

          To enter their phone number because you sent an SMS to them.

          So if there are any costs for sending this SMS it’s on you.

      • tom1337 42 minutes ago

        then google has decided that you no longer should be able to use GMail (for now) and the internet (in the future)

        • mghackerlady 35 minutes ago

          eh, they gave up on trying to control usenet and haven't touched gopher so I'll just go there

    • noitpmeder an hour ago

      I think it's probably enough to get your phone to open your texting app with a pre populated number and message body, then all the user needs to do is hit send.

    • yawnr an hour ago

      It probably opens a prefilled text message and the user still has to hit send. That's the only API I know on iOS anyway.

      • philajan an hour ago

        Can confirm this is what scanning the QR code does. I just went through this to get my Google dev account verified.

    • goldenarm an hour ago

      Regarding how easy simswap is in 2026, it's dangerously stupid from Google to rely on SMS

  • 8cvor6j844qw_d6 3 hours ago

    Recently helped a small business set up a Google Workspace account and we hit a wall during registration.

    Told the owners that if Google is already being difficult during signup, imagine being locked out later with client work on the line. Pulled up a few horror stories about Google lockouts to drive the point home. They ended up with another workspace solution.

    • Aurornis 2 hours ago

      > and we hit a wall during registration.

      What does this mean? The scanning a QR code and sending a text message from this article, or something else?

    • super256 2 hours ago

      With which workspace solution did they end up with?

      • p0w3n3d 2 hours ago

        I assume "next leading brand" ;P

        • cromka an hour ago

          Hopefully that means Nextcloud ;)

    • thrownaway561 an hour ago

      Everyone hates on Microsoft, but their platform is 50x better than Google. Personally nowadays I would be looking at Proton if I was going to setup a workspace for my company.

      • windexh8er an hour ago

        This is hilarious. Microsoft has had many issues and outages with M365 in the last few years. I mean, I guess if you don't rely on mail, then sure.

        • SV_BubbleTime 15 minutes ago

          We are 365 shop… I cannot think of one single time the 365 being down has affected us at all. Maybe you’re right I don’t know. Maybe your region is worse than my region.

        • b112 an hour ago

          If one takes the comment to mean, 50x better for support, I can believe that. After all, 50x almost nothing can be achieved fairly easily.

  • opengrass 2 hours ago

    I got this a few weeks ago, it was a URL like "sms?:number" which tries to pre-fill text in app. Didn't work for me (Fossify) so I had to copy the number and verifier text from that URL and send it manually. It's for saving money spent on providers like Twilio.

  • reconnecting 2 hours ago

    Gmail has been evil both for client privacy as they use email scanning for marketing purposes, and for 'spam' filters that reject legitimate emails.

    The fact that they're introducing QR/SMS/MMS/whatever they want is actually an interesting signal, because it will harm the customer experience, which might result in the growth of responsible paid email services.

    • rapnie 29 minutes ago

      > Gmail has been evil

      It is good to realize that it has never been "Nice Uncle Google" and always an advertisement moloch offering tools to hook their product. All that trust that was bestowed was never warranted.

    • riddlemethat 2 hours ago

      The only “real” competition for Google Workspace is Microsoft if you need a full collaboration solution beyond just email, and 99.999% of customers of such hosted solutions need that full solution. It’s why Dropbox worked even though hacker news users probably roll their own sync solution.

      • reconnecting 2 hours ago

        Tuta, Fastmail, and Posteo are all much better alternatives to Gmail in terms of privacy.

        My comment, as per subject, is about Gmail.

        • daft_pink an hour ago

          His point was just that many business users can only purchase Google’s solution or Microsoft’s solution, because they’re the only services that will offer interoperability with many other security and compliance services and advanced functionality like SSO, third party email scanning, compliance journaling etc. The email market is essentially a duopoly as soon as you need any functionality beyond basic email.

          • windexh8er an hour ago

            The simple fact that you believe this is insane to me. Microsoft?Security and compliance? Ahhh, yes the north star of security!

            No, you don't need either of these companies if you need a corporate stack for communication and collaboration. And anyone who believes Microsoft or Google is doing anything out of the ordinary to protect their users or data is out of the loop.

            • nathanaldensr an hour ago

              It's not about actual security; it's about the appearance of it. It allows CTOs and such to check a box to say "Why yes, our vendor is secure! Look at all their claims! Look at how many other companies use them!" That's it. Safety in numbers for clueless CTOs.

  • xchip 9 minutes ago

    I also receive too much spam, I'll believe in their AI whenever they are able to fix spam.

  • DivingForGold an hour ago

    Won't be registering any new gmail accounts in the future and will gladly dump the ones I have if Google tries to force obtaining my phone no.

  • jmyeet an hour ago

    Everything is going to get so much worse and AI really is to blame. So many websites now have these verification pauses and CAPTCHs because of AI agents. Part of it is agents. Part of it is everyone running their own awful versions of Googlebot.

    Years ago IIRC there was a "bug" where the Android emulator allowed you to create real Google accounts. This was found and I'm sure millions of these accounts were created. There's a whole black market for Google accounts. Whereas I lost a Google account I'd created for a relative because it hadn't been used in awhile and it was tied to a mobile number I no longer had.

    I don't see how this ends without registering for a service like Gmail being tied to your government ID.

  • dsr_ 2 hours ago

    ... and gives me a message on my primary phone: "This number has been used too many times."

  • findbizonline 6 hours ago

    When did it start?

  • spwa4 2 hours ago

    The real problem for privacy is that governments are increasingly outsourcing the verification of identity and bot protection to private companies.

    • carlosjobim 2 hours ago

      Outsourcing? Governments have never been involved in bot protection or online identity verification for anything else than their own websites.

      It's like saying that the government has outsourced burger making to McDonalds.

  • CWwdcdk7h 2 hours ago

    Last time YouTube wanted to verify my phone number it was easier to find a free service to receive SMS than for Google to deliver it to my actual phone. And Google didn't care I "verified" a number assigned to other side of the world.

    • mghackerlady 44 minutes ago

      It's becoming increasingly hard to find a service that lets you see verification messages, and even then google doesn't like a lot of the numbers those services use