Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

But the phone number you have is not 100% in your control. I had AT&T flub something and I lost my number and they assigned me a new one (I was chanting my plan just after they did some merging with someone). Granted its unlikely but I would still use defense in depth and not have password reset be my only login method.


Thats totally fair and really scary since so many services think 2fa means texting or calling a phone number (my bank for example)


It's also why I always opt for 2FA that's within my control: a security key, TOTP, or an email address on a domain I own. That last one is the weakest, since I own the domain as long the registrar says I do but it's better than a corporation I can't get support from if my email account is locked for any reason.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: