Hacker News new | ask | show | jobs
by PeterisP 1639 days ago
The problem is that often adding the phone number just says "2FA" but in reality becomes as another single authentication factor (e.g. in credential reset workflow) - and, given the risk of SIM swap, it may be weaker than proper 1FA e.g. a good password.