4 ms·
This is why you always (always) have backup codes. If a site doesn't provide them (and only allows 2FA via SMS rather than also via Time-based one-time password
by LocalPCGuy 4y ago
This is why you always (always) have backup codes. If a site doesn't provide them (and only allows 2FA via SMS rather than also via Time-based one-time password), that's a huge red flag to me (and yes, I'm aware some very large sites fall into that bucket).
- tjoff 4y agoSo U2F is a red flag? Maybe 2FA should be considered a red flag at this point.
- LocalPCGuy 4y ago2FA by itself isn't a flag to me, only offering 2FA via SMS is. It means to me they did the bare minimum in order to say they offer 2FA.