Hacker News new | ask | show | jobs
by cuu508 1942 days ago
Tell that to Twilio :(

For Twilio accounts, there is an option to add a TOTP secret, and use it when logging in. But, they don't support disabling the default SMS method, and using TOTP exclusively. When you authenticate using TOTP, you still have a fallback option to receive a SMS code.

So, in the case of Twilio, the TOTP feature only improves convenience, not security. At least that was the case when I looked a couple months back. I opened a support ticket about this, and they acknowledged the problem, and that was it.

1 comments

Exactly this. I'd love to not have my mobile not associated with my account.