Remix.run Logo
layman51 5 days ago

You mean to say that if it were enabled on my Google account, then the TOTP numbers for my other accounts are visible via authenticating into Google Account on some other unknown device? Sounds like it could be convenient if you lose your phone, but still risky if an attacker can sign into your Google Account.

jgilias 5 days ago | parent [-]

Yeah. And this is on by default. Without an additional secret.