cross-posted from : https://lemmy.zip/post/71321898
Netzpoltik details that police are able to gain access in this way either through physical access to someone’s phone or by intercepting verification codes via a state-sanctioned phishing attack or intercepting SMS messages via telephone surveillance


You can remove SMS 2FA from a Google account if you have passkeys or hardware security keys registered
But with a always on VPN they constantly ask to verify our identity, even with passkey or phone number.
Even when I successfully verify my passkey, they will still sent a SMS code to my recovery number. It’s almost impossible to bypass that step and try another method button redirect again to the same phone verification page. If I didn’t give my number, then this message appears, “there is not enough information to prove this is your account. try again later.”
Maybe VPN is a factor that triggering their security system.
Does it also include TOTP 2FA?
Not sure. You need att least one form registrerad. I do recommend using multiple.