Hacker News new | ask | show | jobs
by timattrn 1503 days ago
Use a 2fa app with backups, or one that syncs to different devices (e.g. authy). It's distributed TFA. The phone number is not very secure, so I don't think it should be a part of TFA. I therefore agree that it is unwise to allow Google to use it for this. I also have a fake dob on my phone account to make Sim porting harder, but you can't trust that you have control over your phone number.
2 comments

1Password also has a distributed TOTP system.
Bitwarden Family / Pro / Enterprise also has the ability to Setup TOTP based MFA which is then synced to other devices

I use both Authy and Bitwarden