Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Which in itself is a problem: it means the MFA device is not required, if only they have access to my email + phone.



Sure, I know. Just pointing out that, at least for AWS, you do not need recovery codes or a second device for MFA. For me personally, phone+email is good enough for my threat model.


Yes, AWS MFA is very poorly implemented.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: