Hacker News new | past | comments | ask | show | jobs | submit login

This approach is geared at telephone banking. It means no single employee will learn the entire secret during a call. You generally have a regular password in addition to this step.

Why can't I tell a bank employee a time-based 2FA code over the telephone?

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact
