4 ms·
This is true, though I think the grandparent's point was more that it is still a strictly better security situation than before, in that they can't change the p
by FaceKicker 15y ago
This is true, though I think the grandparent's point was more that it is still a strictly better security situation than before, in that they can't change the password and remove your access to the account, but you can instantly remove their access (by password revocation). I'm not sure if he/she actually meant that all you could do was read the victim's mail, but yeah, he's wrong if so.
- mapgrep 15y agoYa, I think that's a good point; we can all agree that two factor auth is a significant win for users and it's good Google has done it. I just think people should be clear on what the keys can and cannot protect you against. You mentioned revocation -- one thing that will motivate people to do timely revokes is being aware of the potential harm of leaving these keys active after they are compromised. From what I recall of Google's setup process, they don't prominently tell people to be sure to revoke their keys in certain situations, e.g. you lose your iPhone, you lose your iPad, you lose your laptop, etc. It's easy to get the impression while activating 2-factor auth that these keys are more limited than they are and that you don't have to worry too much about them.