Hacker News new | ask | show | jobs
by foota 937 days ago
Couldn't you just set up a text service to request a one time token? That way you could fall back to SMS, but it wouldn't be required.

(e.g., anyone could create a service that someone could use, which would allow them to request a 2fa code to be issued over SMS at any time after enrolling it via the OTP pairing process)

1 comments

What happens when the attacker uses that fallback to perform the exact same attack that they perform today?