Hacker News new | past | comments | ask | show | jobs | submit login

How does adding a second factor of authentication to an already good password make it less secure?



because they let you use the phone number to reset the password


Which effectively reduces it back to 1-factor authentication. There's an adage somewhere that is probably worded better but which boils down to your security is only as good as your weakest link.


So you can’t add it as a second factor but not as a recovery mechanism?




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: