Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

SMS is a great option since it supports people with feature phones. But, IMO, SMS should be a fallback, rather than the primary option, since it is network-reliant and subject to a number of attacks that app-based authentication is not subject to.


Couldn't agree more.

I'm not using SMS on any of my 2-step-auth services because I don't want to be locked into owning that phone number (and worry about roaming charges if I travel).

Google Authenticator or similar apps are my first choice.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: