Hacker News new | ask | show | jobs
by shortcake27 934 days ago
It’s impressive how some of the most successful tech companies in the world get this wrong.

If you give your phone number to Google, they will pressure you to enable SMS MFA and SMS account recovery. So your phone number becomes the weakest link into your account, which is pretty bad considering the state of sim swapping.

Google and other companies should make this clear to users. You should never have both SMS MFA and SMS account recovery enabled. If you must, only ever enable one. Ideally, neither.

1 comments

They effectively outsourced IdP to telcos for free. That's the part that's wrong.