Hacker News new | ask | show | jobs
by beauHD 1329 days ago
In the EU, PayPal defaults to SMS 2FA. I had to go out of my way to enable a Yubikey to login. U2F should be the default, but not everyone owns a Yubikey, so they would piss many people off demanding Yubikey-only 2FA.

Alongside this, they sometimes send an SMS OTP to verify it's you making a purchase. I don't want PayPal anywhere near my SMS inbox. It's so backwards.

1 comments

Supporting passkeys and hardware keys for MFA should be mandated by statute. I know, heavy handed, but witness the current auth/identity challenges making the need clear.