Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

How does adding a second factor of authentication to an already good password make it less secure?


because they let you use the phone number to reset the password


Which effectively reduces it back to 1-factor authentication. There's an adage somewhere that is probably worded better but which boils down to your security is only as good as your weakest link.


So you can’t add it as a second factor but not as a recovery mechanism?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: