Hacker News new | ask | show | jobs
by butz 1512 days ago
Does using 2FA for GMail login actually add more security? Especially considered that to enable it, first you have to use dubiously secure SMS 2FA.
1 comments

It's still an additional authentication factor, so in most circumstances, yes it would benefit security. However, you can (and should) use U2F for 2FA, which involves hardware making cryptographic assertions that cannot be phished or man-in-the-middle'd. It's possible to remove SMS as an option after turning this on in Google settings, but unfortunately not so with many other providers.