this is a thing i dont like. i dont like cell phones, and will never own one. seems every thing they do to make your email secure is counter-intuitive. frankly they seem to be doing everything possible to make email easy to hack. first thing they are doing is enforcing a really complicated hard to remember password. this makes people use the same password for multiple accounts. password recovery is also really counter-intuitive. thats how hackers get into your email in the first place. they follow chains of accounts collecting personal information, and then eventually get enough data to get into your account through your secret questions. that brings me to another point. why does everything that you do on the internet need to link up with every other thing you do on the internet. this makes it possible for your security to be compromised across the board. why does everything you do on the internet have to depend on an email account? i have 4 email accounts, 3 of them i keep mostly blank and use them when signing up for forums and stuff. the email i actually use doesnt get used to sign up for things.
here how i would manage security.
1. ABOLISH PASSWORD RECOVERY SYSTEMS!!!! you loose it its gone, just dont be a moron.
2. instead of making users follow 300 rules about password complexity, just make them have a really long password. 20 or 30 characters or so, minimum. maximize permutations.
3. make accounts stand alone. stop requiring some other account to sign up for another account. thats sets you up for cascade failures in security.
4. stop telling people to cough up non-relevant personal data.
5. use ip location checking. ip addresses are usually localized to a specific region, so its easy to determine the approximate geological location of the user. use this data to create a baseline usage. if you unexpectedly teleport from the us to nigeria and back again, that should be a MASSIVE RED FLAG that something is amiss. this would need to be optional, and possible to tell it if youre moving, changing internet providers, going on vacation, and your general radius of usage.