4 ms·
I think this is a positive move. My gmail for instance is one of the better-protected services I use: I have a ludicrous password and 2FA. The reset options o
by herghost 12y ago
I think this is a positive move. My gmail for instance is one of the better-protected services I use: I have a ludicrous password and 2FA. The reset options only include dialling my mobile (not voicemail) or emailing another account (which isn't otherwise associated with me to anyone who knows me), which is also protected by a strong password.
Why not allow Apps to not use passwords in this case?
In addition (for me) the app would be on my mobile, which is passcode protected (and fingerprint). Beyond that security you have full access to my email anyway, so what's any additional app password going to provide?
since you need the device (which you're presumably steeling) AND the passcode for it, does this make it 2FA? I think I've read Apple claim as much in a Data Protection document, but I wonder whether you can really count the device you're trying to log in TO as one of the Factors?