"Building proprietary, impossible-to-understand Rube Goldberg mechanisms based on associations between accidental aspects of my life (location:phone number pairs, for instance) is not a security system."
It is a system for building better profiles of potential targets for advertising. Gathering data is a means to improve online advertising services to Google's customers.
The more data you volunteer, the more their online advertising services can potentially improve. That is one way to look at it.
From another perspective, all the "security" measures are
a red flag for me that Gmail accounts are high risk if using for important, personal matters. (And that people are increasingly using it for such things.) The available solutions to that problem from the user's perspective should include the option to stop using Gmail, not simply to support Google's rollout of the next set of Kafkaesque "security" processes that incidentally always require more privacy sacrafices.
Giving me a notice that a User-Agent header changed (by suggesting they have detected a "new device") is not my idea of "security", but it reminds me that this data point is among the ones they are collecting for their online advertising services. It makes me wonder what assumptions and proclamations someone might be making based on such "evidence". I did an experiment where I saved a session cookie for an account I registered and used it outside the browser weeks later, without any User-Agent header. It worked flawlessly and I got no warnings of a "new device". Makes one wonder what is in that cookie and how long it will last. Is it restricted to IP address/location. If it never expires, then if an attacker ever gets a session cookie and the user never logs out of that session, the attacker will be able to "silently" use the account, forever. Yikes.