logoalt Hacker News

Terr_today at 9:21 AM1 replyview on HN

I don't think it should be the sites' responsibility to guess whether the browser session is the have device will receive an SMS message... The fact that it is SMS is already bad anyway.

Time-code apps or passkeys are a different story.

1. You should be able to make backups.

2. There's nothing to intercept in plaintext.

3. The all can (unlike SMS features) be locked down by default and require a second layer of unlocking, so that they usually aren't accessible to someone who grabs your phone out of your hand.


Replies

account42today at 10:33 AM

It absolutely should be the Bank's concern when this is how 99% of their customers will use it. Some even have deliberate integration between the baking and 2FA apps.