3 ms·
So what about a opt-out at account level? Something in the account settings, like this: [check] Allow sign-in from javascript disabled browsers. WARNING etc. (
by ifdefdebug 8y ago
So what about a opt-out at account level? Something in the account settings, like this:
[check] Allow sign-in from javascript disabled browsers. WARNING etc. (usual warnings about security etc.)
Edit: because users who know to use long passwords and 2FA do exist and don't need all that extra security stuff ...
- ankit219 8y agoI used a long and supercomplicated password for one of my accounts that i access intermittently. Why I have it is a long story, but I only log into it once or twice a month to check if there is something that needs my attention. Usually the login is in incognito, guest mode, and even from different locations and machines. Google asks for a second factor (i dont have it on for my accounts) like phone verification for my usual accounts (not so complicated password) but not for the one with complex password. So I think the level of extra steps/security is linked with how complex your password is. Not so sure if this is a good thing or bad. But, I hope they should continue basing their security measures based on the security measures you take.
- linker3000 8y agoI asked LastPass to generate me a long and complicated password for a new Office 365 account only to have it rejected as too long because it was over 16 characters. Sigh.
- relic 8y agoIt's probably the switching of devices that raises the level of security.
- Jonnax 8y agoIt costs money to support and a miniscule amount of users would care. The majority of Google's customers also don't pay for an account.
- chatmasta 8y agoMaybe one reason is because google doesn’t know which account is trying to login before the login page, so how could they remember that security setting before attempting to serve JS?
- moolcool 8y agoI don't understand why anybody concerned about having JS on a login screen would want to log into Google in the first place. I imagine there's a tiny overlap between "Runs NoScript" and "Trusts Google"
- ValentineC 8y ago> So what about a opt-out at account level? Something in the account settings, like this: > [check] Allow sign-in from javascript disabled browsers. WARNING etc. (usual warnings about security etc.) It sounds a bit like what Gmail's doing with their "allow less secure apps" login option, except that's more for allowing IMAP logins using password instead of OAuth.