Hacker News new | past | comments | ask | show | jobs | submit login

What is the tl;dr on why SMS is bad for 2fa?

If your password recovery also operates over SMS, it's actually 1fa.

Because it's easy for hackers to talk the telco customer service reps into switching your phone number from your device to the hacker's.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact
