Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Thanks. This thread was giving me the impression that adding 2fa with SMS to a system would make it more vulnerable somehow.


It does if the provider uses the phone number to reset the password.


...in which case it becomes an "alternative factor" instead of a "second factor".




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: