4 ms·
What you say is true of actual 2FA, which only adds security. (Unless, maybe, you take into account risk compensation[1], which is probably magnified when SMS 2
by osteele 9y ago
What you say is true of actual 2FA, which only adds security. (Unless, maybe, you take into account risk compensation[1], which is probably magnified when SMS 2FA is less secure than users think.)
However, SMS “2FA” is often used to mean SMS-based password reset, where SMS can be used instead of the password. With SMS-based password reset, SMS subtracts a factor (EDIT: or divides by two[2]?), instead of adding a factor as in 2FA.
This is the case with the OP article. The text of the article is unclear about whether it means 2FA or password reset, and the title does include the term “SMS-based 2 Factor Auth”. However, the example issues that the article links to are all cases of password reset, not 2FA.
[1] https://en.wikipedia.org/wiki/Risk_compensation https://en.wikipedia.org/wiki/Risk_compensation
[2] I propose that SMS-based password reset be called “Half-Factor Auth” (HFA or ½FA), to distinguish it from 2FA.