My point was simply that Google sees enough attempts to compromise Gmail accounts that I believe them when they claim widespread attacks using valid passwords are common enough that passwords are broken.
> Yes, MFA is a good idea. But that doesn't mean it's enough to prevent attacks like the one in question.
It would have stopped this one, in several ways: according to Honan's writeup, it would have halted things at a key point in the chain of account compromises. Yes, it's true that you have to trust companies - but that's always been true, even 100% off-line, as any victim of identity theft could tell you. The key point is that having any sort of MFA schema would have contained the damage to one company, halting the cascade.
> Yes, MFA is a good idea. But that doesn't mean it's enough to prevent attacks like the one in question.
It would have stopped this one, in several ways: according to Honan's writeup, it would have halted things at a key point in the chain of account compromises. Yes, it's true that you have to trust companies - but that's always been true, even 100% off-line, as any victim of identity theft could tell you. The key point is that having any sort of MFA schema would have contained the damage to one company, halting the cascade.