Hacker News new | ask | show | jobs
by groffee 1512 days ago
A lot of 2FA is security theater and doesn't provide any actual protection.

If your phone gets taken by the police (or stolen), with an authenticator app or sms they can get into your account easily but you're locked out.

A hardware key is the way to go but even then there's no guarantee the police wouldn't take that as well, and most people think having an app on their phone is enough.

And 'email alerts' are even worse, if someone has taken your computer and has complete access to your accounts, an email saying "is this you?" is just gonna make them laugh.

1 comments

To be fair the threat model for most people isn't the police or any other physical attack - instead it's remote attacks such as phishing, malware, etc.