Hacker News new | ask | show | jobs
by methodover 3160 days ago
That was one of the ideas that we pitched to the CEO. Only sensitive actions would require 2FA. CEO shot it down, saying it would require too much work on the part of the customer.
2 comments

Why not give customers the option to choose to enable it then?
The kind of customer that reuses passwords is probably the kind that won't enable 2FA if it's optional.
Sure, but then it's on them rather than you.
Users will go through the work if you incentivize the behavior.