2
0 Comments

A thing I don't think has been remarked upon enough…

A thing I don't think has been remarked upon enough:

Using email to distribute 2FA codes for logins to e.g. banks is a choice to outsource to Google detecting anomalous activity (e.g. hacked accounts / reused passwords).

Probably not wrong that Google has comparative advantage.

And, of course, non-Google email providers, because email is an open protocol that literally anyone can host.

(Don't know whether to laugh or cry about that, honestly, since it's literally true but rounds to false practically.)

on November 12, 2018