Hacker News new | ask | show | jobs
by edent 4350 days ago
The flaw is "Thanks - we've texted your 2FA code to +44 7700 900 171."

That's primarily to tell the user which phone to check - which isn't a bad thing.

They should probably fix it by saying "we've texted your 2FA code to the phone number ending 171" - or similar.