Hacker News new | ask | show | jobs
by bradknowles 1683 days ago
Don’t do 2FA over SMS. Just don’t. That’s a big bag of hurt that is just begging for someone to stand up and come looking for it.

Once you eliminate that, what part is left of your business model?

1 comments

I fully agree with you on the theoretical reasons why SMS-based MFA is bad and should stop being used at some point.

In the meantime, try explaining a random user how to setup and use a TOTP for your application, I wish you good luck.

Once every business is able to enable TOTP-based MFA for their applications, it'll be a great day for cyber and my side project will cease existing ¯\_(ツ)_/¯.