Hacker News new | past | comments | ask | show | jobs | submit login

1. One SMS every 90 days, because the security teams have no idea how MFA works (I know, I work there). Even if you hop devices. See https://try.popho.be/psd2.html

2. It's just a little dev step away: http://blog.cmpxchg8b.com/2020/07/you-dont-need-sms-2fa.html . Phish kits will evolve, UX will still be bad, and phishing will still happen.

See also https://sakurity.com/blog/2015/07/18/2fa.html




> 1. One SMS every 90 days,

Wow that's bad.

Here in Norway we use a system called BankID that uses the SIM in your mobile and it does it every time I log in.


Some banks know security better than others

And yes the login one might be every 90 days, but to do a transaction there might be an extra one

(yes Germany did away with paper tans (2fa codes) in 2019 yay - thankfully not all banks are that stupid)




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: