3 ms·
It’s worse in a lot of implementations because often SMS is often used as part of a recovery flow in cases where you lose the first factor. I find it more secu
by Negitivefrags 2y ago
It’s worse in a lot of implementations because often SMS is often used as part of a recovery flow in cases where you lose the first factor.
I find it more secure in some contexts to never give a company my phone number at all if possible, so that it simply can’t be used as any kind of authentication no matter what.
- smeej 2y agoYeah, I'd draw a hard line between "SMS 2FA is better than no 2FA" and "SMS should never become a single-factor recovery method." I agree SMS should never be an option for single-factor recovery.