logoalt Hacker News

ipaddryesterday at 5:41 PM1 replyview on HN

Why is email based 2fa bad but phone good? There are classes of issues you get through phone 2fa compared to email


Replies

ceejayozyesterday at 6:02 PM

Typically, you can also reset password via email, so it's really only one factor. Compromised email = compromised server.