Hacker News
new
past
comments
ask
show
jobs
points
by
ipaddr
22 hours ago
|
comments
by
ceejayoz
21 hours ago
|
[-]
Good. E-mail based 2FA is bad, and they appear to support TOTP too as an option, as they should. Wish they supported U2F though.
reply
by
ipaddr
19 hours ago
|
parent
|
[-]
Why is email based 2fa bad but phone good? There are classes of issues you get through phone 2fa compared to email
reply
by
ceejayoz
19 hours ago
|
parent
|
[-]
Typically, you can also reset password via email, so it's really only one factor. Compromised email = compromised server.
reply