Hacker News new | ask | show | jobs
by genevra 400 days ago
What's the actual method that can be easily deployed at scale then?
2 comments

I'd argue that there isn't one: you have to offer multiple choices. Auth through any TOTP app, Yubi key, pre-generated codes, mailing a physical code generator, etc.
Email + SMS + generic time-based OTP seems quite enough for imho