>This summer I learned how to get into, well, everything. With two minutes and $4 to spend at a sketchy foreign website, I could report back with your credit card, phone, and Social Security numbers and your home address.
I simply don't believe this. Absent a keylogger or some massive security breach with Google themselves, I can't think of any way an attacker could get into my gmail account short of rubber-hosing.
The author hand-waves all of this by saying "let's say you're on AOL". Well, let's say I'm not. Let's say I have an account at Gmail with a > 20 character password and a > 20 character answer to the password reset question. If someone can break into that within a few minutes, they are severely undercharging at $4.
I agree that it's hyperbole, but there's one more factor to consider:
"The hackers persuaded Apple to reset my password by calling with details about my address and the last four digits of my credit card. Because I had designated my Apple mailbox as a backup address for my Gmail account, the hackers could reset that too, deleting my entire account—eight years’ worth of email and documents—in the process."
For anyone who had an email account prior to Gmail's launch in 2005, I'd wager there's an excellent chance that they initially linked their prior account to their Gmail account while signing up. In fact, reading this article has made me realize that I'm in the exact same boat; I still have my Gmail address linked to an ancient, dormant email account on a relatively-insecure service (I trust them more than AOL, but not nearly as much as Google).
You're an exception. Most people are not as well-protected. Being key-logged is not as unlikely as you seem to think, even if you're protected from all known attacks, new ones could result in your password being harvested along with thousands of other people's.
If you're the target of a directed attack, you have even more to worry about.
No, because I don't like the idea of being dependent on some external factor to be able to access my email account. If there's an emergency and I find myself naked with my wallet and phone gone in the middle of a foreign country, I want to be able to access my emails.
You can (and should) use a list of one-time passwords that bypass the two-factor authentication. Google generates them for you, and you surely can memorize one for emergencies.
Your Gmail account is not necessary to retrieve your credit card, phone, and Social Security numbers. And finding someone's home address is trivial, usually for free.
I simply don't believe this. Absent a keylogger or some massive security breach with Google themselves, I can't think of any way an attacker could get into my gmail account short of rubber-hosing.
The author hand-waves all of this by saying "let's say you're on AOL". Well, let's say I'm not. Let's say I have an account at Gmail with a > 20 character password and a > 20 character answer to the password reset question. If someone can break into that within a few minutes, they are severely undercharging at $4.