Ask HN: When is 2FA not enough?
I was under the impression that username + password + 2FA token was sufficient for anything public. What am I missing?
I was under the impression that username + password + 2FA token was sufficient for anything public. What am I missing?
Undercover Boss Star Killer Base Edition https://youtu.be/FaOSCASqLsE?t=3m48s
2FA is a weak link, it's been proven it's easy to social engineer access to your phone account/number. Once someone has your phone they will receive all your 2FA notifications and once they can reset your email password with it they have the keys to the castle.
Plus if you lose your phone, then you're locked out, without your printable one time use keys, that you probably didn't print.
There has to be something better.
It also helps a bit with fraud (users who create multiple accounts) because it's usually harder to come up with several working mobile phone number. I say usually because professional fraudsters will find a way around that hurdle.