logoalt Hacker News

declan_robertsyesterday at 2:35 PM1 replyview on HN

At this point it's pretty clear 2FA SMS is just a ploy to get PII customer data under the guise of security


Replies

bityardyesterday at 3:03 PM

The ONLY accounts I have that require SMS and offer no other 2FA are financial institutions. They already have more information on their customers than most other businesses I can think of. Heck, I WANT my bank to have my phone number so they can call me if there's ever a problem. I just want insecure SMS to stop being the only minor hurdle between a fraudster and my life savings.

Companies do SMS because their VP of security compliance demands 2FA and because it's easy and has mature existing third-party vendor support. No tinfoil hat needed for this one.

show 2 replies