Hacker News new | ask | show | jobs
by rurp 975 days ago
Is there any evidence that Google needs to mess with authentication flows? My mental model of the median Google account holder is that they have a bunch of photos/emails/docs/etc that are extremely valuable to them and their family, but of little value to criminals. With a dynamic like that, the security only has to be so high to deter random hackers and making it too difficult or confusing will ruin a lot of valid accounts and do much more harm than the criminals would have.

There are reasons to be skeptical of Google's motives here given their history of wanting to create user lock-in in various ways, and caring more about shiny new tech than general user experience.

1 comments

There is incentive to gain access to personal emails. Not enough for spear phishing but enough for generic phishing. Access to email allows you to pivot to every online service in a person’s life.