Hacker News new | ask | show | jobs
by snarf21 1564 days ago
Most companies suck at security. Most users suck at security. Convenience > Security. It is sad that SMS as 2FA account recovery actually adds an attack vector. It is less bad as an out-of-band check if you have a password authentication from a known and finger printed computer.