Hacker News new | ask | show | jobs
by fr2null 1866 days ago
If that is the case though, you are not really enabling SMS 2FA. It is just SMS (1F) authentication.

Real 2FA would (theoretically) never make your account less secure than 1FA, because even if the second factor has 0 security, it shouldn't decrease the security of the first factor.

However, it is true that this may not always be the case for imperfect implementations, like your example. I can aldo imagine that social engineering might have a higher succes ratio if the intruder can say "it really is me! I have the correct second factor, I just lost my first factor...".