Google latest sign-in update is making a lot of people very angry
productforums.google.com
productforums.google.com
Secondly, it breaks almost all password managers including Lastpass, and it breaks a lot of extensions like these[1]
[1] https://chrome.google.com/webstore/detail/quick-login-for-go...
Type username/password = ~1s each
Single keypress = ~0.1s each
Page load = ~2s
Before: username + tab + password + enter = 1 + 0.1 + 1 + 0.1 + 2 = ~2.2s
After: username + enter + page load + password + enter = 1 + 0.1 + 2 + 1 + 0.1 + 2 = ~4.2s
Roughly doubling the amount of time it takes to enter your information is significant and annoying.
Odds are, people compromise on many or all of those things (even smart or meticulous ones). What you sacrifice with a password manager is a single point of failure. Although, that's a bit dire, generally (and arduously) you could reset those passwords one-by-one if you lost your master password and/or database.
What I like though is that the exposure of your master password is controlled by you and limited between your keyboard and the application (and the various few things in between; the OS, perhaps RAM, etc). This is usually a lot more narrow than the path your passwords usually take (your browser, http, their server). Because it's a single password (and I'm not limited to a site's stupid max character or other constraints), I can make it as obnoxiously long as I'd like--and I don't have to try 3 or 4 obnoxiously long passwords because I can't remember if I typed the wrong one or if I typoed the right one until I get locked out of that website.
Like I alluded to earlier, I also like knowing how long ago I changed my password, what it used to be (in case my db is updated and I didn't quite change my password like I thought I did), unsecure or duplicate passwords (as I migrate them over), or if there has been a database compromise on their end and I though update my password. I'm kind of surprised nobody has released features to automatically change passwords on specific sites.
It may make them angry but its pretty clear Google is working towards a:
"Username" -> "Auth Factor 1; Maybe not Password" -> "Auth Factor 2; Also maybe not Password" model.
Have the users enter their user/pass in the first page. The second and third pages then asks the Auth Factor II or Auth Factor III fields
For the business "this is wasting my time" complaint I just read a whole lot of: you're about to spend an hour or so reading inconsequential emails instead of doing anything productive anyways. What is another 500ms?