Hacker News new | ask | show | jobs
by shaftway 1392 days ago
I would never use a hardware 2FA on any service with no other way in. But that doesn't make them not-valuable. For me the ideal setup is a service that offers a SMS verification code or a 2FA token. The 2FA is far more convenient for me, but if I don't have it the SMS is there as a backup and I can get in to unregister or register a new 2FA token.
1 comments

I’d rethink SMS as a secure authentication vector. Too easy for SIMjacking to happen.