4 ms·
s/permanently/trust for 30 days/ Still not great, but it's not permanent. You can also log out other sessions in google apps, not sure if that resets the dont
by 5h 13y ago
s/permanently/trust for 30 days/
Still not great, but it's not permanent.
You can also log out other sessions in google apps, not sure if that resets the dont-do-2factor-auth bit though.
- Dylan16807 13y agoYou have to reenter the password in thirty days but you never need the second factor ever again (at least in some cases, which in security terms might as well be all cases). The important part is in fact permanent. I'm rather skeptical on the security offered. Edit: I'm still looking for some kind of documentation for it, but I know this firsthand. I set up two factor authentication several months ago and chrome has not asked for anything other than the password since. I can even go into the two factor settings with only my password, which gives me complete control to make unlimited single-use codes, or authenticate a different phone, or turn the whole thing off.
- Achshar 13y agoThere is no way for you to read the one time passwords. You can only disable them from dashboard or make new ones. The parent comment was about keyloggers, and the don't-require-two-factor-auth checkbox is for browser cookie session only. So there is no way for a keylogger to exploit the checkbox. The attacker can only know your email and password, not your browser's cookie data.
- Dylan16807 13y agoI was not talking about application-specific passwords. I was talking about the ability to make 'backup verification codes' which can be used anywhere a second factor is needed. Once they have your first login they have a permanent all-powerful backdoor to your account unless you go in and hit the button that resets all logins. But more importantly, your threat model is rather urealistic. Why would you trust an infected and keylogged computer to not be able to steal something as unprotected as cookies? You're right that in some kind of situation with a 'pure' keylogger you're safe, but you could get the same level of safety by doing something silly like log in with an on-screen keyboard. I think such a narrow threat model is misleading.