3 ms·
Regarding the "SMS-2FA is not only worthless, but harmful" claim, it's true, but only in the sense that widespread "lazy" SMS 2FA deployments stifle U2F, which,
by packet_nerd 6y ago
Regarding the "SMS-2FA is not only worthless, but harmful" claim, it's true, but only in the sense that widespread "lazy" SMS 2FA deployments stifle U2F, which, I believe, should just be the standard across the board[1]. Of course SMS does help, just not as much or in as many attack scenarios (and is more of a UX pain too).
[1] The common HN objection which you alluded to is "but it's so hard!" It's really not. Passwords are hard! If only I could have back all the hours I've spent trying to help my grandparents remember their passwords. I have a U2F token plugged into the side of laptop and nothing could be easier than tapping it to get in. Implementation might be hard, but come on, that's our job.