HACKER Q&A
📣 herodoturtle

Gmail popup – already on vs. count me in


So today I open gmail and I get this popup on the top right, asking me about 2 step verification - which sounds good and all that.

But then it shows two buttons, the first says “Already on” and the second (which is highlighted blue) says “Count me in”

I’m not sure how to interpret these (and therefore which to click).

If it’s already on then surely it won’t present me with the option to click it? So what does the alternative count me in do?

And there’s no close / x button either. Annoying.


  👤 more_corn Accepted Answer ✓
I’m a security person. I fully support 2fa. I’ve implemented it dozens of times for companies where I work, companies I’ve owned, clients I’ve worked for.

The pop-up you’re talking about disgusts me. Not just because it’s terrible but because it colors a good thing.

If you can’t say “no” you didn’t choose. Action taken without choice is forced.

Forcing your user to do what you want is a display of disgust.

Not the way to delight your user. That’s not a way to partner with a user to increase security.

Note to google product people. STOP DOING THAT.

Note to other product people. Don’t ever do that.


👤 elahd
I figured this was:

1) An experiment to test the level of familiarity that non-technical users have with two factor authentication. That is, does a person who incidentally enabled SMS 2FA understand that having to enter an SMS code every time they log in is a pattern called "two factor authentication" as opposed to just some weird part of Google's login workflow.

2) An artifact of a user's security preferences living in a protected space that can't be accessed by Gmail's frontend. Gmail's dev team got an order to encourage users to enable 2FA and this is the best they could do.

3) A ploy to get people to review their 2FA settings -- or to be sold Titan Security Keys. Google's security team has sent me several emails over the past few months encouraging me to buy these, claiming that I'm at an increased risk of a targeted attack. I'm not fully bought in to their motives.

(All conjecture.)


👤 Saris
I was confused as well, 2FA is already on but it asked me anyways with the popup.

👤 seFausto
I've had 2FA on google for a while, so when I got it I thought it was to enabled an authenticator app like Duo or Google's own app, so I clicked "Count me in" then the box had a loading gif and showed that it was on.

👤 IE6
This popup made me panic that someone had gotten access to my account (like through some side channel such as calling google and pretending to be me) and disabled 2FA somehow...

👤 toast0
Saw this popup on google maps today, seems like it's in a lot of places. I just ignored it and did my mapping, slightly obscured.

👤 ffhhj
Seems like they just created a new dark pattern: either do what we say or tell us a lie. Disgusting.