Hacker News new | ask | show | jobs
by indrora 1636 days ago
The reason for having SMS-based 2FA as a default is that it's At least something.

Adding a U2F token and having SMS as a backup means that you don't have people locked out because their yubikey failed -- which happens.

Discord is trying to solve some of the bootstrapping problems that arise from "oh fuck my computer and phone were both stolen" -- which, again, happens.