Hacker News new | ask | show | jobs
by staticassertion 1637 days ago
That sounds fine to me tbh. It's worth knowing, but it's not weak. Email is a pretty good 2FA in terms of security, it's just not great in terms of usability, so it makes for a good fallback.

Attacker with MP + email access is pretty severe.

I wish more services used email as a 2FA instead of SMS.