Hacker News new | ask | show | jobs
by id_ris 3982 days ago
This is a reason to not verify over SMS and to instead use the Google Authenticator app. It seems easier to socially engineer a SMS redirect than to obtain the mobile device and bypass its login authentication.

If you are going to verify over SMS, don't have your SMS messages forwarded to email as that would render your 2fa pointless.