I went through it to register just now. No QR code required. Same flow as it has been for years:
1. Personal/Child/Business
2. First/Last
3. Pick email
4. Date of Birth
5. Backup email / Skip
6. Password
7. Enter phone number
8. Confirm with 2FA code
9. Done.
I just made the email testregistrationflow@gmail.com and have since forgotten the password. So that’s one burned. But feel free to try testregistrationflow1@gmail.com and see if it works without a QR code.
The headline is clearly a misstatement of what is a specific flow for someone to make many Gmail accounts programmatically.
Probably depends on how "trust worthy" you seem to Google for them to trigger this requirement. Things like using Linux, using Firefox, using a VPN, etc.
You can reach a point where the phone number you used for 2FA has been "used too many times" and then you're stuck in the middle of registration. There doesn't seem to be any documented limit anywhere and the only solution people have been able to use is find someone else to help you verify with their phone number. What makes this more difficult is when you get logged out of one of your accounts, they ask for a phone number for 2FA to login, you provide the same phone number you used originally (even though it is not officially associated with your account, just to verify registration), but that fails because your number has apparently been used too often. So now you can't even log in to your valid account that already exists. Sure, should have added some other form of 2FA or a passkey to the account, but why can't I verify with the same number I used originally? And just to top things off, you can't use your Google Voice number for 2FA account verification when signing up for another Google service.
The number is not associated with your account, it is just used to verify legit account creations. Retroactively nuking an account due to using a "banned" phone for account creation verification would be wild and not in Google's best interests.
I'm constantly spinning up new accounts for clients and I've used my number on way more than 4 accounts, so maybe it is on a rolling basis over some time period?
That's certainly an interesting idea - mostly everybody should know someone who has a gmail account, so if you get a couple invites a month, that should be plenty and the setup would
Well I was about to say destroy scammers, but I just realized that they would send out spam to places where you could gamble your invites for Real Cash(TM) or just straight up buy them.
This would lower the creation of accounts, but then they would be rarer and worth more to spammers, since a spamming gmail would be rare.
And we would hear sob stories of people getting their accounts closed for inviting spammers.
Not without some kind of delay function and probably filtering/evaluation of which new accounts get this capability...
Everyone here should be familiar with exponential growth of n-ary trees. If you can get one of these accounts and each new invitee gets to invite 2 more, you can already have accounts gone wild.
So, the scammer should send an invite to a real person from one percent of the accounts in the tree, wait a few months, then flip the evil bit on 90-95% of the accounts they registered. If the whole tree is cut off the reputational damage is really high (10,000 valid users nuked because of actions other accounts took...)
Not really, even "legit" marketing providers have massive automation rigs to warm email addresses, make them behave naturally and email each other in rings for a bit before using them for cold outreach.
So they'd just do this to farm invites if they needed
This is why I always ignore these headlines until I see the change firsthand. In this case it wasn't even an article, only a brief forum comment, for a topic as complex as spam protection. Might not be an A/B test, could just be someone with a low-trust profile (eg Arch Linux ipv6 in Singapore with multiple Gmails).
1. Personal/Child/Business
2. First/Last
3. Pick email
4. Date of Birth
5. Backup email / Skip
6. Password
7. Enter phone number
8. Confirm with 2FA code
9. Done.
I just made the email testregistrationflow@gmail.com and have since forgotten the password. So that’s one burned. But feel free to try testregistrationflow1@gmail.com and see if it works without a QR code.
The headline is clearly a misstatement of what is a specific flow for someone to make many Gmail accounts programmatically.