Hacker News new | ask | show | jobs
by Gud 1366 days ago
What do you think is wrong with 2FA?
2 comments

As a user, it's not fast, user-friendly, or fail-tolerant. And all three of those vary heavily depending on the company implementing the 2FA.

A username/email and password is pretty simple and straight-forward. If I lose a password, I can reset it via my email. Therefore, the only account that should even consider MFA should be my email, since it's a gateway to everything else. But that also means my email shouldn't have to be connected to 20 other services.

2FA is fine. Being forced to use a mobile phone for 2FA is wrong.