Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> I think that depends on how it's implemented and how their account recovery process is done. If they give SMS special status and use it with few or no other data to recover accounts when you're locked out, then adding SMS 2FA might actually significantly decrease your security for that account by allowing someone to gain access with just the SMS capability.

Very true and very dangerous. Do account recovery procedures technically count as a authentication factor? I've always though about them as a separate thing. For example alterative email addresses, physically visiting a building, etc can be used to recovery an account but may never part of the actual login process.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: