Google will soon switch on two-factor authentication by default
theverge.com
theverge.com
When you travel abroad, is out of battery, break your phone, etc, etc, you're 100% out of your digital life until you can overcome the 2FA limit. And this happens in the moments you need it most.
Why do you think they did this?
Do you think building Google Analytics into Authy had anything to do with it?
Repeat after me --- until proven otherwise, assume everything Google does has privacy invasion built into it. This includes "caving".
I also had an issue with an account that had a 2FA option but via an app that proved dangerous because I accidentally forgot about it when switching phone devices (same number) and just about locked up my entire account trying to get it working again.
If you mandate 2FA, it has to work and it has to leave the customer better off. If not, why bother?
But just say "no" to Google and a lot of the issue goes away.
How is privacy destroyed by using a well implemented 2FA solution? I understand TOTP standard supports generating tokens locally with no network access required.
Most 2FA; including Google, default to using your phone number or worse, access to your device from their software.
Post your phone number and I will show you how this destroys your privacy.
They probably already have all your personal info so why not verify it so they can be sure they have it right?
It's really what's best for your own protection. It's not like Google is "evil" or something. Mooo!
> Privacy is destroyed
How?
> and losing your phone is multiplied into an even bigger disaster
Not if you are using a U2F key instead of your phone as your second factor.
Post your phone number and I will show you.
Not if you are using a U2F key instead of your phone as your second factor.
Same problem, different device. Phones and hardware keys are both easy to lose or break/destroy.
I know how posting a phone number destroys privacy.
What I want to know is how 2FA does. For which you have provided no explanation.
From the article, Google "standard" 2FA uses your mobile device. So by your own admission, giving others (and particularly Google) your number or access to your phone destroys privacy.
People are bad enough with passwords. They'll be worse with recovery keys.
Otherwise, you'll have a bigger problem than ever before.
And this is called "progress"?
(I imagine someone at Google made sure this is possible and I thank them for it)