2 ms·
This 'just to be safe' procedure happens when Google thinks a bad guy is logged into your account. The bad guy might have changed the password, changed the 2f
by pifm_guy 4y ago
This 'just to be safe' procedure happens when Google thinks a bad guy is logged into your account. The bad guy might have changed the password, changed the 2fa, stolen login cookies or other malicious things.
What Google ought to do is to display a message saying:
* Google suspects someone else, or a virus, has access to your account with malicious intent.
* Google will help you secure your account.
* It is necessary to prove you are the legitimate account owner before we can allow you access to the account. To do this, we will ask for you to log into the account with as many possible devices and methods as possible. Into each device you should type '7867' after logging in.
* We ask this because a malicious actor or virus probably will only have control of a few of your devices, passwords or security keys, so we can identify you as the true account holder because you have more.
* We will then lock out the malicious actor, and you can change any passwords or security keys they used. If one of your devices was used by a virus, we'll block it until you have reset it.