Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The only 2FA I'm using is the one of my bank, because I must (there are regulations.)

I stopped logging in into GitHub since they enforced 2FA on my account. Luckily no current customer of mine is using GitHub. They are on Bitbucket and it does not require 2FA yet.

A number of services that I use ask me to enable 2FA. I skip the offer everytime.

The worst 2FAs are SMS based: not because of the (in)security of SMSes but because I don't receive SMSes when I'm outside of my country.



>because I don't receive SMSes when I'm outside of my country

What?! I've never had that issue.


I never received a SMS from Italy when I was on vacation in Australia in 2019. Apparently my phone contract would allow them but either the phone company did not honor its terms or banks didn't send SMSes to roaming customers. I ended up using Italian payment services that either had their own app or other methods to perform 2FA. I also had an Australian SIM but there were no chances to associate it to my accounts. I guess that it's fair, because a foreign number all of a sudden is a red flag for a stolen account.

And nobody sent SMS to me, everybody used WhatsApp or similar services.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: