Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> With that in mind, at a glance the idea of changing your two-factor auth credentials "for security reasons" isn't completely unreasonable.

No?

How do you change your 2FA? Buy a new phone? A new Yubikey?



For TOTP it's as simple as scanning a new QR code.

I agree that rotating 2FA should ring alarm bells as an unusual request. But that requires thinking.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: