Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Application-specific is just a friendly name.

Also this password doesn't give you full access to your Google account. You cannot log into Google web apps this way (AFAIR). Thus you won't be able to mess with account settings (passwords etc). Before you can change critical account settings Google asks you to provide your traditional password again.

Your comment is a bit harsh if not FUD.



'Application-specific' is IMHO not just a friendly but a misleading name. They are simply not application-specific.

Using one of these so-called application-specific passwords, you can delete calendars, mails and contacts. That is critical enough for most users.

An additional concern is the usual 30-day authorization you give in order to avoid entering your 2-factor token again and again. Is there any way to de-authorize such a 30-day authorization?

Anyway, I don't rule out that my perspective might be too strict. For must users, the whole Google 2-step authentication system is probably a very important step towards improved security.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: