Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

For one thing, there are a lot of security holes that let people reset passwords by getting a code via SMS

For another, what's the point in having 2FA if one of the factors is completely insecure? It's just an annoyance at that point, and a good way to ... tie your account to your phone number, which just coincidentally happens to be the primary key for most advertising tracking services. What a coincidence



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: