Hacker News new | past | comments | ask | show | jobs | submit login

Can you explain how I'm weaker with 2FA via SMS than without 2FA? I agree SMS is not good 2FA but your statement is more extreme.



Because companies routinely and silently use SMS 2FA as SMS 1FA.


But that's not an inherent problem of SMS 2FA. It's just bad implementation.


No, the inherent problem of SMS is that it can be stolen/redirected. Given that, and given that companies are too eager to use it as 1FA, you shouldn't use it.

If I'm giving advice to companies, I say "don't use SMS 2FA as 1FA" (well, I actually say "don't use SMS 2FA at all, it's too tempting for a support person to use it as 1FA"), but this thread is about the user, and as a user, you shouldn't use SMS 2FA.


I wonder if companies that have your phone number and do such careless things as "phone-number based 1fa", will not also simply do that if you don't even have 2fa enabled... As long as they have your phone number, they'll abuse it.

So you are not against phone based 2fa or 1fa, your are against giving companies your phone number. But them, if they are soooo careless to try phone based 1fa when they can get away with it, they are also probably open to some social engineering.

In the words of RMS: "We should all try to make those companies fail."


If I didn’t have SMS-2FA enabled, they would not have been able to take control of my email address without guessing the password.


“But we send YOU and sms on YOUR phone number you left in our systems!”




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: