Hacker News new | ask | show | jobs
by chatmasta 1907 days ago
A TOTP code response is trivial to implement on the client. So if you wanted this to be meaningful, you would need to force users to use SMS 2FA, which is widely considered insecure. Not a great solution IMO.