SMS 2FA Insecurity
This cluster focuses on criticisms of SMS-based two-factor authentication (2FA) due to vulnerabilities like SIM swapping and SS7 attacks, with recommendations for secure alternatives such as TOTP or hardware keys.
Activity Over Time
Top Contributors
Keywords
Sample Comments
Why are you using SMS 2FA?
You shouldn't be using sms as 2fa anyways. It's barely better than no 2fa at all. Use an authenticator app.
Please stop supporting sms for 2FA. It's not better than nothing, it's worse than nothing. Given the extent of technology workers on hacker news please work to remove this antipattern from your products.
Related: SMS 2FA is not secure https://news.ycombinator.com/item?id=27447206
SMS 2FA is not secure. Lots of HN posts about it:https://hn.algolia.com/?q=sms+2fa
Ironically SMS 2fa is less safer than just using a password
SMS 2FA is better than nothing if, and only if, you don't allow password resetting by owning the SMS.
Don't use SMS as 2FA, it's insecure. TOTP is a much better solution.
I think you need to re-visit your SMS support decision. SMS for 2FA is not secure, at all.
Why are you using SMS 2FA anyway?