Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You really shouldn’t use SMS 2FA. SIM swapping does happen. This kind of depends on the jurisdiction though. In some countries operators won’t reassign the phone number willy-nilly.

Still, better to just not do SMS auth. These days Yubikeys are not that expensive. Get three, register them all at the most important places, and put one at a parents’ place or similar.





I agree entirely.

But the point I was making that IF the website does not allow Yubi THEN SMS is almost certainly available, and you should use that as a backup mechanism.

Why ? Some sort of backup mechanism is better than none at all.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: