Quote:
Originally Posted by Quoth
If you use a decent different password for everything the Google mandated 2FA isn't needed. Also mysteriously it's NOT needed for Google's mail client on Android nor on any browser used to access Google Web mail.
|
That's not true. You need to 2FA-authenticate at least once when you sign into your Google account, which necessarily happens before accessing your mail via either of those routes. (However, on Android let alone iPhones U2F stuff is still rather embryonic and many U2F tokens only talk USB and not all phones can handle that, so it's possible it was skipped there for a long time simply to avoid locking people out of their accounts completely -- but if it is, it's skipped for any logins to your Google account on there, not just for "Google's client".)