Hacker News new | ask | show | jobs
by majewsky 3203 days ago
> most security threats these days seem to be external to the device you are using.

It depends. From the top of my head, the smartphone is the most common second factor, so an attacker that's on your smartphone may be able to log onto most services that have 2FA. Or alternatively, they can DoS your own attempts to log into these services by deleting SMS, or just sending the phone into a reboot loop. (Of course, "targeted DoS" is not in everyone's threat model. But still, I have more peace of mind using a dedicated TAN generator device instead of my phone.)