Hacker News new | ask | show | jobs
by penguindev 4250 days ago
This article is conflating two things:

- two factor login (you need password + sms text)

- account recovery (using only a phone) THIS IS DUMB.

I only use an alternate email for recovery (my wife and I cross). Thus, each recovery account is still 2FA secured.

There's already been a story floating around about a young kid charging his dad's credit card because of the phone recovery option (he had the android phone in this case). This is NOT the same as 2FA auth.