Does "Yes, this is my device" defeat the purpose of 2-Step?

A knowledge base article about Does "Yes, this is my device" defeat the purpose of 2-Step? provided by the UC Berkeley IT Service Hub - Knowledge Portal

Security of "Yes, this is my device"

Actually, no! Even if an attacker knew your username and CalNet passphrase, they would still need to access your specific physical computer and use the same web browser to take advantage of the "Yes, this is my device" feature.

Because the "remember me" session is tied to a unique browser cookie on a specific device, the probability of an attacker exploiting this is extremely low. This makes “Yes, this is my device” a safe and convenient option for users on trusted, non-public computers.


See also: KB0012156 - Do I need to verify every time I log in?