> Google Group Product Manager Christiaan Brand told BleepingComputer that due to the possibility of end-to-end encryption causing users to get locked out of their own data, they are rolling out this feature carefully in their products.
I know everyone's pro-E2EE here but this rationale should be taken seriously. I absolutely believe E2EE is an important option to have, but it also makes sense for it not to be the default.
If you keep all your passwords synced in Chrome, for instance, none of them are behind E2EE either. If you use Gmail, all your password resets will go to your Gmail which also isn't E2EE. If you use Google Voice, SMS login codes will go to that, also not E2EE. It's not like syncing Authenticator data is less secure than anything else, and Google accounts are already awfully secure generally.
For most people, adding a new password/key just for Authenticator is just one more thing to forget/lose, especially since it's something they'll probably only touch every couple years. I think it's good to add E2EE as an option, but only for the minority of users for whom the necessity of extra security outweighs the risk of losing access entirely.