Google still needs to know the secret. All authenticators are based on a shared secret model, so the same possible attack vector that bit RSA.
Google still needs to know the secret. All authenticators are based on a shared secret model, so the same possible attack vector that bit RSA.