Hacker News new | past | comments | ask | show | jobs | submit login

This sounds like an argument for adding hardware multi-factor auth in google. It's not a panacea, but a good starting point that can't be easily spoofed or hijacked.



They already have it: https://support.google.com/accounts/answer/6103523?hl=en

And it adds nothing, since it still has fallbacks to the existing systems.


You should be able to remove less secure authentication mechanisms via accounts.google.com, after setting up a security key


You still need to keep atleast one backup method in case the security key is corrupted/broken/lost etc.


Print out a recovery code and keep it somewhere safe.


You can have two or more security keys associated with your account on Google.


Oh really? I thought that it forced you to go back to the app if you use a non-U2F browser.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: