Hacker News new | past | comments | ask | show | jobs | submit login

Which you should do anyway because relying on SMS is only slightly more secure than not having 2FA enabled at all...



SMS is still an option if you have a working 2FA Authenticator on GitHub. And even if I went through the trouble to disable it, I disagree. There are conceivable ways people could get to my email to initiate a password reset without getting to my phone, such as snatching my laptop from me while I'm working at a coffee shop.




Consider applying for YC's W25 batch! Applications are open till Nov 12.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: