Hacker News new | ask | show | jobs
by tuangeek 1990 days ago
Ideally no. You want a 2fa to be different from your email. But it comes down to the user if they want to enable it or not. If they don't have it enabled the services default to sending a code to the users primary email. My guess is to prevent people from being compromised from malicious sessions.