• 4 Posts
  • 586 Comments
Joined 1 year ago
cake
Cake day: August 2nd, 2023

help-circle











  • SMS is fine for 2FA, as long as you can’t use it for anything else, like a password reset.

    Once the SMS is used for account recovery, it’s now 1FA with a terrible security hole.

    If you have complex, single use passwords, and have SMS 2FA, then it’s pretty ok. Not the best security, but at least better than a most.

    Obviously offline time based passkeys are better for the 2FA, but typically the real problem is how to get into an account if you’ve lost one part of your login.