Even though the post is a bit clickbaity there is still one thing I learned from it and if somebody cyber security expert can confirm this: - there exists a powerful token (like a master key) using which a person can read all my emails, drive, etc bypassing the email alert and unknown device check?
If you mean the one that's used on your phone to access everything, yes, although it doesn't bypass the email alert (the linked clickbait goes into how they have to click "allow device" on their already-signed-in phone). When you log into either the Google.com website or into an Android device your token needs permission to do everything you'd expect to do as a user - gmail, drive, etc. This attack is basically a bro…
Re: I stole the data in millions of people’s Google accounts
#21I only had to click 'allow device' because I had 2FA enabled on that account. For anyone who doesn't, that step is not required.