Hacker News new | past | comments | ask | show | jobs | submit login
Gmail will lock important settings behind a pop-up 2FA challenge (arstechnica.com)
4 points by DemiGuru on Aug 24, 2023 | hide | past | favorite | 1 comment



> This security pop-up is all about trying to stop attackers that have compromised your account. If someone steals your laptop, or a malicious remote desktop app turns on, and you're already logged in to Gmail, the pop-up should at least keep the attacker away from the worst settings. Filters are a security risk since a lot of other sites notify you of purchases and sensitive changes to your account with an email, and a common first step in an attack is to hide these emails with a filter. Forwarding and IMAP both duplicate your incoming emails to other places and could allow people to quietly spy on you or steal credentials.

Seems reasonable. I guess people who use sms 2fa are gonna be annoyed, but this is a non-issue for yubikey and passkey users.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: