Earlier quoted context omitted.
> a 24 hour lockout to allow the owner to notice an attempt on their account. I've been pretty careful to ensure that I don't lock myself out of my account (multiple U2F keys, strong password saved in password manager with backups) But if a determined attacker kicks this off just as I'm stepping on a flight from Sydney to London, 24 hours isn't going to be enough. (I should add also - I'm a mostly happy Fastmail cust…
For an attacker to exploit this, they will have to know that you are going on such a trip. This means that attackers who don't know much about you already are less likely to bother, and also raises the bar for even the focus attackers. Nothing is foolproof, but many things can be useful.
They could also compromise other people who need to know my plans and don't have the same security practises as me.
I think about this stuff and minimise as best I can, but my account security shouldn't be dependant on it.