There's a bright highlighted warning that says "STOP! Only proceed if you arrived this page by scanning a login barcode at google.com. Otherwise, do not proceed!"
Will users read the warning? I would—and did—it really grabs your attention given the fact its background is yellow and takes up so much of the iPhone screen.
I suppose there are probably other safeguards as well, given that this is Google—maybe timed expiration?
Comments
That seems particularly open to abuse.
Couldn't I just link someone to a copy of the QR code and be automagically logged in as them?
It raises an approval screen on the phone. It says
By proceeding, you give another computer access to the following accounts: * blah@gmail.com
STOP! Only proceed if you arrived at this page by scanning a login barcode at google.co. Otherwise, do not proceed!
(start with GMail) (start with iGoogle)
Ah, I see. Thanks for adding that info
There's a bright highlighted warning that says "STOP! Only proceed if you arrived this page by scanning a login barcode at google.com. Otherwise, do not proceed!"
Will users read the warning? I would—and did—it really grabs your attention given the fact its background is yellow and takes up so much of the iPhone screen.
I suppose there are probably other safeguards as well, given that this is Google—maybe timed expiration?
I left the page open and after finished reading comments (a minute or two) in HN, the page gave me this popup dialog:
[Alert] Login session has expired. Press Ok to reload.
This + 2 Factor-Authentication = Pretty Damn Secure.
but those two are different things. They are not complimentry (from what i understand)
I assume it is valid for only a short period like the code generated from the Google Authenticator app.