Hacker News new | ask | show | jobs
by robbya 2347 days ago
Why? It's not "secure" but it's more secure than nothing.

The paper mentions some websites that claim to use SMS 2FA, but actually use SMS as a single factor for password resey. While that's really bad I think the solution is to fix those broken implementations not to stop using SMS 2FA everywhere in favor of using nothing.

1 comments

The paper also said, "websites should eliminate SMS based MFA altogether".