18 ms·
Consider 3 situations: 1. Google does not require 2FA. 2. Google DOES require 2FA on an account, but only requires the second auth if "suspicious activity" cr
by ergot_vacation 5y ago
Consider 3 situations:
1. Google does not require 2FA.
2. Google DOES require 2FA on an account, but only requires the second auth if "suspicious activity" crops up.
3. Google requires 2 auths on each and every login.
On 1, if a bad actor picks up your phone and tries to log in, they will fail if you haven't saved your login, or succeed if you've been lazy and saved it. In the latter case, that's really on you (and you might still be able to get your account back even then, if they didn't fully and quickly reset password and other details!)
On 2 however, they will try to log in, fail, and trigger a lock-down that can only be lifted with both auths. One of which you don't have anymore. Congrads, you've just lost your account!
3 is the same as 2, just for different reasons. As soon as that phone disappears, you don't have the second auth, and you're screwed.
And don't even bother with anything that isn't a phone. We both know nobody in the general public is using anything other than text for this. And some older folks don't even have that! Add on to this that SMS can be easily hacked, and it's pretty clear this whole system is a joke.
- Jxl180 5y agoYou just put in your back up codes to restore access. That’s why the backup codes/words exist. If I lose my crypto wallet or it gets stolen, I go to my bank, get the words from my safe deposit box, and use those words to seed my new wallet. Doesn’t have to be a bank — a home safe or filing cabinet will work, but when my phone broke I had zero problem restoring my 2FA on my new phone using the backup words.