Hacker News new | ask | show | jobs
by JshWright 2355 days ago
Is it though? Implementing SMS 2FA often means a site will never bother implementing anything better.
1 comments

Not implementing SMS 2FA doesn't mean a site would implement anything either.
No, but it's increasingly becoming the expectation that 2FA should be available.

Going from no 2FA to some 2FA is a more likely transition than going from bad 2FA to good 2FA (since bad 2FA still checks the 2FA box).