Hacker News new | ask | show | jobs
by tgsovlerkhgsel 2473 days ago
The reason why companies love SMS 2FA is because most people keep their phone number. In a scenario like you described, most people would walk into a <whatever their provider is> store, show ID, and get a new SIM.

This way, the company using SMS 2FA has effectively outsourced this recovery path to the phone companies. Instead of handling recovery (and potentially liability for getting it wrong) themselves, they can just tell you to go recover the phone number. And when the phone company gets it wrong, you get stuck in a nightmare of finger-pointing instead of having a clear culprit to hold responsible.