4 ms·
In terms of user security, that's just not a good idea. Google has likely prevented an absurd number of account compromises (and therefore identity theft, fraud
by shallot_router 9y ago
In terms of user security, that's just not a good idea. Google has likely prevented an absurd number of account compromises (and therefore identity theft, fraud, personal information leakage, espionage...) by recognizing logins from new devices and unfamiliar locations. Google's user account security practices are pretty much the best in the business.
It's silly to think Google doesn't already know everything about every device you log in from, so that horse is already out of the barn and running on the highway privacy-wise. They might as well use that information to actually protect their users since they're already using it for advertising.
- yorwba 9y agoI'm sure that Google's decision has improved the account security of the average user, but I'd really like it if there were some way I could signal them that I'm not an average user. My password likely has more entropy than the hash they check it against; if that gets compromised, the attacker also has access to any other information Google would use to identify me. Which is a joke anyway, since "which city do you usually log in from" is hard to answer when you've been using a VPN for more than a year. I dread the day when they make 2FA mandatory and my account security becomes vulnerable to a social-engineering attack hijacking my phone number.
- RasputinsBro 9y agoI thought I had a way around that, but no. You CAN add a phone number, then ask you use FreeOTP token, then delete the phone number. Great, right? No. Because if you click that "I forgot my password / don't have access to my 2FA" button, they do let you use your phone number to identify yourself, even though you've deleted your number from your google account. Fuck these people.