Hacker News new | ask | show | jobs
by sadfnjksdf 4446 days ago
Ok, valid point- to clarify, when I said 2-factor SMS, I was assuming a 30-second TOTP like Google's.

If you don't use TOTP, someone can login to your account just by knowing the password which they can use from almost anywhere. If you were to only use TOTP, they'd need your phone. To me them stealing your phone is tougher than stealing or guessing your password.