A knowledge base article about Does "Yes, this is my device" defeat the purpose of 2-Step? provided by the UC Berkeley IT Service Hub - Knowledge Portal
Actually, no! Even if an attacker knew your username and passphrase, they would still have to access the same physical computer and use the same browser to take advantage of "Yes, this is my device" The probability for this is so low that it makes “Yes, this is my device” a safe and convenient addition.