Hacker News new | ask | show | jobs
by RamblingCTO 885 days ago
Hm, that's true. I'd say it's not good 2fa, but it is 2fa tho. Matter of definitions.
1 comments

2fa means BOTH factors are needed. the situation you are discussing here is not password and email but password or email. either one would work.

i have seen services that send a token to your email every time you log in or when you log in on a new device or when you haven't logged in in a long time. that would indeed be a form of 2FA. but these services also allow you to reset the password through email, so it's not exactly 2FA all the time like most other 2FA setups.