Hacker News new | ask | show | jobs
by brandontreb 2050 days ago
It's crazy that companies are still using SMS for 2FA. TOTP solves this problem is a much more elegant way and is immune to such attacks.
1 comments

You might have set up TOTP and removed SMS 2FA on Gmail but don't forget to remove your phone number as a recovery method as this can be equally devastating when exploited by SIM Swapping.
Ahh, this is a great tip. I’ll have to double check now.

Thanks.