|
|
|
|
|
by robbya
2349 days ago
|
|
You're talking about account recovery, not 2FA. A website can use my phone number for account recovery even if I'm not using SMS as 2FA. I agree with everything you said about SMS for account recovery. Account recovery that uses a phone number is weak. There was a paper on HN this week that detailed this. However, if we are going to compare SMS 2FA (I.E. password plus code sent over SMS) against just password, SMS 2FA wins. In both cases I need to steal your password, the SMS part is an added challenge although it's easier to bypass than many people want. Given SMS 2FA and any other 2FA option, SMS 2FA loses. |
|
SMS as an authentication factor weakens the security because of all of the additional behaviors associated with the account provider which are inescapable.