Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If it is enough with access to the phone number, no password needed, then it is no longer 2FA.


Sure, but 17 websites do this. For those websites you introduce significant weaknesses if you enable SMS 2FA.

https://www.issms2fasecure.com/




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: