|
|
|
|
|
by Matt_Cutts
5476 days ago
|
|
There's also the case of resetting your password for various other services. If someone can get access to your email account, it might not matter whether your actual webhost or domain registrar password is in your Gmail. The bad guy can force a new password or password-reset link to be sent to your email account, then intercept and use that link. I already use a strong/unique password for Gmail, and I do my best not to login from untrusted devices, but adding two-factor authentication reduces the potential attack surface that much more. |
|