Deleting someone’s business off Heroku
peternixey.com
peternixey.com
Two-factor authentication could be made more secure by requiring you to reply to a text message with the answer to a security question that couldn't be found on your phone (e.g., the name of your favorite comic book character).
If someone steals your keys, they stil have to find a time when no one's home, and it's still hard to steal things from a physical location quickly. Once you notice your keys are gone, you can call a locksmith and rekey the house.
That's why the article recommends a time delay. There should be enough time to realize that your access has been compromised, and nothing destructive should occur faster than that time limit. Ideally, the time limit should be configurable, so you can go on a vacation and know that even if someone hacks into your email the day you leave, nothing will get committed until your return.
I don't think expecting people to protect their email and TOTP secrets is unreasonable, but it does go to show how vulnerable you are if your unlocked phone is stolen and you don't react quickly.
Don't give your phone to people you don't trust if it grants them this kind of access, and if somebody gets a hold of your phone or you lose it, change your passwords.
The problem is that standard practices are lacking.
"No"
...
"Erm, what do you think you're doing, get your hand out of my pocket!"
No-one touches my phone.