Hacker News
new
past
comments
ask
show
jobs
points
by
ceejayoz
22 hours ago
|
comments
by
ipaddr
21 hours ago
|
[-]
2FA has been in place for years through email but this new requirement forces a phone.
reply
by
ceejayoz
21 hours ago
|
parent
|
[-]
Good. E-mail based 2FA is bad, and they appear to support TOTP too as an option, as they should. Wish they supported U2F though.
reply
by
ipaddr
18 hours ago
|
parent
|
[-]
Why is email based 2fa bad but phone good? There are classes of issues you get through phone 2fa compared to email
reply
by
ceejayoz
18 hours ago
|
parent
|
[-]
Typically, you can also reset password via email, so it's really only one factor. Compromised email = compromised server.
reply