Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

2FA is so overrated. You can so easily do a sim swap to get access to a particular phone number and bypass 2FA.


The problem isn't with 2FA, the problem is with SMS-based 2FA.


True, and that's why you shouldn't use SMS 2FA. The unfortunate part is when that's the only method offered.


TOTP and HOTP 2FA are unbreakable and supported by literally everyone. Who still does SMS 2FA anymore?


Lots, unfortunately. With no way to opt out




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: