Hacker News new | ask | show | jobs
by mehrdada 1346 days ago
I was not suggesting SMS 2FA when I referred to "Smartphone-based solution". I meant relying on Secure Enclave or alike on the smartphone as the second factor in a challenge-response fashion that makes the "OTP" bound to a specific domain and thus unphishable.
1 comments

Sorry I didn't see the SMS part was a quote of the parent.