Hacker News new | ask | show | jobs
by Dylan16807 1071 days ago
2FA apps will never be perfect and allowing careful access is not going to undermine them.

And the alternative is taking a picture of the QR code.

> Additionally just because someone is using a device that doesn't mean that the current user is the owner of the device.

Yeah that's why you make the owner authenticate. It would be ridiculous to use that as a reason to make escalation impossible.