Hacker News new | ask | show | jobs
by causal 793 days ago
Right. The SMS 2FA risk is overstated IMO - at worst it makes it as insecure as password-only, and at best it creates a roadblock for attackers that can be significant for locked SIMs.

But SMS account recovery is definitely opening the door to attack.