Hacker News new | ask | show | jobs
by bvrmn 1341 days ago
This! There is no additional security for aware users with MFA. Make MFA turned on by default, ok, but for god's sake if you provide only SMS-based 2FA, allow it to be disabled.