Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Are you advocating for OTP 2FA? If so, your concern about losing your phone and losing access to your accounts is still an issue.

At the end of the day, OTP is more secure for the obvious issue with mobile carriers being phished into SIM jacking. But, I've personally had 0 luck convincing any business person that OTP is the best thing to use because (and this is a true statement) users are dumb and lazy and don't want to go through the process of downloading an app on their phone and setting up OTP. Plugging in your phone number for SMS is way easier.



TOTP can be stored in things like 1password and shared between devices, if you want.

I don't mind if SMS is an option, but I would prefer it not be the only option and certainly not the only backup option (weakest link and all that).


You mean TOTP in an authenticator app right? To my knowledge SMS 2FA sends you an OTP


Yes sorry TOTP.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: