Why is Google Enforcing Multi-factor Authentication?

Is this option the most preferred best practice?


  • Total voters
    15
With appropriate controls like limited login attempts the burden is in the providers court.

I've never cared for this particular control-- some view "maximum attempts" to be a good security measure, but I view it as an easy way to target a DoS attack (violation of "availability" in the Security Triad). (Edit: in conjunction w/ IP heuristics, maybe not so much... but then again, it's easy to change an IP.)
 
Back
Top