Hacker News new | ask | show | jobs
by my8bird 5171 days ago
While I like 2 step authentication I wish Google would get rid of SMS password reset. With this enabled all a person needs is your phone to gain access to your account. Given that police can grab you phone whenever you are stopped this means they can "hack" your account at the same time. Another example could be a cleaning person at a hotel finding your phone. Just two examples off the top of my head. Basically, SMS password reset makes your phone the golden key.

http://support.google.com/accounts/bin/answer.py?hl=en&a...

1 comments

As long as you have a pin lock on your phone, the cleaning person nor the police will be able to do anything with your phone.
It's not that hard for law enforcement to get your PIN. e.g. http://blog.agilebits.com/2012/03/30/the-abcs-of-xry-not-so-...
What about if the phone can be rooted?