What's more plausible -- Google 2-factor was disabled, or a user re-used the same login/password on a site without 2-factor? Passwords will be with us for a long time to come. Employers should buy employees 1Password or equivalent for their own safety and require long unique random strings for every 3rd party account. Employers can control that somewhat but can't force vendors to implement 2-factor.
Comments
What's more plausible -- Google 2-factor was disabled, or a user re-used the same login/password on a site without 2-factor? Passwords will be with us for a long time to come. Employers should buy employees 1Password or equivalent for their own safety and require long unique random strings for every 3rd party account. Employers can control that somewhat but can't force vendors to implement 2-factor.