Hacker News new | ask | show | jobs
by danmur 1924 days ago
I'm not sure it's better, at least not in all cases. If you can reset your password or login without password using SMS, and you had a strong password, it could be worse.
1 comments

that would be a veryy incorrect implementation of 2FA. Wouldn't be surprised if some service works that way, but would def. be unfortunate
Some services work in exactly this way; it's like using a magic link to log you into a website in the browser from an app on your phone/computer.