<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Potential security problem with Google Sign-In, even with 2FA when accessing my account. in Security and Permissions</title>
    <link>https://www.dropboxforum.com/t5/Security-and-Permissions/Potential-security-problem-with-Google-Sign-In-even-with-2FA/m-p/776460#M15629</link>
    <description>&lt;P&gt;Hey &lt;SPAN style="background: var(--ck-color-mention-background); color: var(--ck-color-mention-text);"&gt;&lt;a href="https://www.dropboxforum.com/t5/user/viewprofilepage/user-id/1845869"&gt;@icab_80&lt;/a&gt;&lt;/SPAN&gt;, welcome to our Community!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let me ask a few things, to make sure we're on the same page.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You mentioned "&lt;I&gt;If I activate 2FA beforehand from my PC and then use Google Sign-In, then I get an SMS code in the same phone where I'm trying to log in from&lt;/I&gt;". Is 2FA currently enabled for your Dropbox account?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm asking because if 2FA is enabled on a Dropbox account, you'll still need to enter a Dropbox multi-factor authentication code before logging in with Google. Is this not the case when you use your mobile app?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let me know more, and we'll take it from there!&lt;/P&gt;</description>
    <pubDate>Mon, 10 Jun 2024 17:42:50 GMT</pubDate>
    <dc:creator>Megan</dc:creator>
    <dc:date>2024-06-10T17:42:50Z</dc:date>
    <item>
      <title>Potential security problem with Google Sign-In, even with 2FA when accessing my account.</title>
      <link>https://www.dropboxforum.com/t5/Security-and-Permissions/Potential-security-problem-with-Google-Sign-In-even-with-2FA/m-p/776440#M15628</link>
      <description>&lt;P&gt;I have an Android phone with a Google account. If I install the Dropbox app, the login screen prompts me to use Google Sign-In to log in to my Dropbox account. If I accept, I get automatically logged in without needing my username and password. If I activate 2FA beforehand from my PC and then use Google Sign-In, then I get an SMS code in the same phone where I'm trying to log in from.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This means that, even if I don't use Dropbox on my phone and only use it from my PC, anyone who has access to my phone could download the Dropbox app and access my account without needing my username and password, even if 2FA is activated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'd appreciate if anyone could tell me if I'm doing something wrong and this is normal behavior, or if this is a security problem, and in either case, how can I avoid it and completely disconnect my Google and Dropbox accounts from each other. Thank you!&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2024 17:33:47 GMT</pubDate>
      <guid>https://www.dropboxforum.com/t5/Security-and-Permissions/Potential-security-problem-with-Google-Sign-In-even-with-2FA/m-p/776440#M15628</guid>
      <dc:creator>icab_80</dc:creator>
      <dc:date>2024-06-10T17:33:47Z</dc:date>
    </item>
    <item>
      <title>Re: Potential security problem with Google Sign-In, even with 2FA when accessing my account.</title>
      <link>https://www.dropboxforum.com/t5/Security-and-Permissions/Potential-security-problem-with-Google-Sign-In-even-with-2FA/m-p/776460#M15629</link>
      <description>&lt;P&gt;Hey &lt;SPAN style="background: var(--ck-color-mention-background); color: var(--ck-color-mention-text);"&gt;&lt;a href="https://www.dropboxforum.com/t5/user/viewprofilepage/user-id/1845869"&gt;@icab_80&lt;/a&gt;&lt;/SPAN&gt;, welcome to our Community!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let me ask a few things, to make sure we're on the same page.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You mentioned "&lt;I&gt;If I activate 2FA beforehand from my PC and then use Google Sign-In, then I get an SMS code in the same phone where I'm trying to log in from&lt;/I&gt;". Is 2FA currently enabled for your Dropbox account?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm asking because if 2FA is enabled on a Dropbox account, you'll still need to enter a Dropbox multi-factor authentication code before logging in with Google. Is this not the case when you use your mobile app?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let me know more, and we'll take it from there!&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2024 17:42:50 GMT</pubDate>
      <guid>https://www.dropboxforum.com/t5/Security-and-Permissions/Potential-security-problem-with-Google-Sign-In-even-with-2FA/m-p/776460#M15629</guid>
      <dc:creator>Megan</dc:creator>
      <dc:date>2024-06-10T17:42:50Z</dc:date>
    </item>
  </channel>
</rss>

