(no title)
deepsun | 4 days ago
Or yours, for not caring about 2FA. It's been a common practice for many years, and strongly recommended by most identity services, as well as OWASP and NIST recommendations.
What would you do in Google's place?
deepsun | 4 days ago
Or yours, for not caring about 2FA. It's been a common practice for many years, and strongly recommended by most identity services, as well as OWASP and NIST recommendations.
What would you do in Google's place?
wl|4 days ago
If Google wanted to lock me out of my account for my own good until I enabled 2FA, fine. But as GP stated, they abused the recovery email addresses to force 2FA on people and ended up locking some people out of their accounts.
dataflow|4 days ago
The rest of your complaints make sense but this one is bizarre. It's a recovery email, isn't having access to it the entire point? Like what else did you think it was supposed to be there for beside being accessible?
Google clearly misused it for something else, and you have a strong argument they shouldn't have. This one sentence just needlessly weakens the argument.
8cvor6j844qw_d6|4 days ago
Best treat all org controlled email address as temporary.
Telaneo|4 days ago
This probably doesn't comply with the relevant recommendations, but cutting a user of from their email is worse in my opinion.
deepsun|4 days ago
mindslight|4 days ago
Google is one of the rare places I actually see positive value to 2FA. Compare with say banks, where it being demanded actually decreases my security. But regardless, it should not be forced.
deepsun|4 days ago
Yes, some banks implement it silly, like SVB requiring biometric login in order to scan one-time QR 2FA code from their app (biometric login is less secure), but you don't have to use the QR code, can use regular 2FA without biometrics.
But even then having 2FA is 42 times better than not having it.
deepsun|4 days ago
They certainly did a proper thing forcing people to use 2FA AFTER multiple emails over the years recommending to turn it on, and warning that they will enforce it, which they did.
saidnooneever|4 days ago
if you make an app it is not your customers responsibility to secure it with additional actions from their side..if it is, you need to make it mandatory and guide them step by step.
you cant after a while enable some toggle.and tell people to fuck off and its the fault of their ignorance to not know some technical details.
most consumers of these services dont know shit about IT and they should not be burdened with it..any product that demands it is either only meant for tech savy people or more likely lazily and badly engineered by money hungry people who see opportunity to make more money in user's issues.
deepsun|4 days ago
That's why Google sent them multiple emails explaining what it is and recommending to turn it on. What else could Google do?
happymellon|3 days ago