Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I have removed all SMS based 2FA from every account that allows it and you should too.


I'm a bit confused how this is relevant. Authy is a OTP app, nothing to do with SMS.


Authy uses SMS based recovery of your entire account, a weaker link that a single service using SMS based OTP


You can always disable multi-device, so it can act like a regular OTP auth app.


and we should do product liability lawsuits on every service that only allows SMS based one time passwords, if they don't allow a client side only option


Why? 2fa doesn't meaningfully add security if you're using decent passwords, and SMS-based 2fa is no less secure than no 2fa


just because SMS is vulnerable to SS7 attacks


So you're saying no 2fa is more secure than SMS 2fa?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: