Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

2FA means something [only] you know and something [only] you have (the phone number), the 3rd factor is usually something you are (biometric).

So using a password and the SMS on the phone is still 2FA as far as I know.

However, I also consider my home PC to be safe enough that I don't want 2FA on it. Nope, banks apparently don't want to waste money on considering this user story. Or that what about registering multiple tokens/phone numbers. Got a new phone? Just burn the old one, you can't have backup login methods!



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: