All security is a trade off. For a good chunk of people that is a rare enough occurrence that it is a good trade off for them.
All security is a trade off. For a good chunk of people that is a rare enough occurrence that it is a good trade off for them.
But I do wish that people on standard accounts could just disable their forced “Google Prompt” authentication method and just use their own 2FA security keys with fallback to backup codes.
You’ll be able to sign in securely with just a passkey or device prompt.
So, if I want to, say, authenticate my Gmail account with Fastmail or ProtonMail, I can't also be using Advanced Protection. [0]
With Google Workspace, admins can allowlist OAuth applications registered with Google APIs for users who use Advanced Protection. Consumer accounts have no such feature.
I am not arguing the logic; I understand it. I just wish it were different. I suspect that passkeys are one stepping stone on the road to increasing account security baselines to be more like Advanced Protection, which may ultimately give me what I want one day. Wishful thinking, perhaps.
[0] These are OTOH examples, which may not be accurate as of this writing.
Irrelevant to the problem of "I want to just disable phone prompt of 2FA without everything else included with Advanced Protection" - there's no intrinsic "security tradeoff" here, just bad and overly restricting design decisions by Google.
Except most people are operating under a flawed assumption that the trade-off with Google is like a trade-off with any other institution - that is, if the worst happens, you can get a human on the phone, or visit a branch office, and get the issue sorted out. This critical fallback is, unfortunately, missing for Google and many other on-line service providers.