Hacker News new | ask | show | jobs
by lxgr 656 days ago
Sure, but please make it optional.

I've seen a couple of enterprise/corporate services switch to the "OTP via email" pattern (usually as mandatory 2FA), and I hate it, because there's no way for me to autofill that email OTP, unlike for e.g. WebAuthN or TOTP.