Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think at some point goolge used SMS 2FA as a sole factor in account recovery. So there, you really were worse off with SMS 2FA enabled.


This is really a criticism that Google called their system 2FA but actually was using it as a sole factor. That's bad security and bad naming. Had they actually used it as a second factor, then you would have seen a security benefit.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: