Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's really unclear to me why you think that email would be involved in any other capacity than 2FA in this scenario.

Are you imagining that email is used in some other additional way in the authentication process, such as account recovery ?



You've never done a password reset? That goes to your email. If your 2FA is over email too then that isn't 2FA. Because you only need the email to take over an entire account


So I see the problem now, your model includes a hidden assumption that password resets go to email -- this is not always the case.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: