
Now you might think, oh it's the phone number connected to this account? Fuck no, you can put in any random phone number and they will just send you a code.

I put in a new phone number that Google has not seen from me before, they just sent it a code, and it worked. Literally all this does is verify if user has a phone number. This does no user authentication, it is only a burden to users with phones, and would lock out people without a phone. Literally if my password gets leaked or guessed, this "2FA" would let any "hacker" just waltz in. It makes no sense. Why is this a thing?