Hacker News new | ask | show | jobs
by Farfromthehood 2124 days ago
Sendgrid user for many, many years.

I believe we disabled 2FA because it broke /prevented our client's ability to send via SMTP. No idea if they've fixed the issue (and honestly don't care). Make security easy to adopt of you want us to implement it.

Also, organization-wide, we don't use 2FA that requires a mobile phone number/SMS (because we don't trust vendors with our phone number).

*IIRC, Sendgrid initially only offered 2FA via SMS, but now you can also use an authenticator app.

1 comments

Phone 2FA is broken by default.

Yes, it broke SMTP and it also broke all API access until they kinda-fixed API keys. Pretty much anything you used basic auth for at a touch point.