Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's certainly safer than only using a password if you use the same password on lots of sites, since the odds of any password database being hacked are higher than the odds of your phone being targeted.


Thanks. This thread was giving me the impression that adding 2fa with SMS to a system would make it more vulnerable somehow.


It does if the provider uses the phone number to reset the password.


...in which case it becomes an "alternative factor" instead of a "second factor".




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: