Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

All of this is valid!

But it would be even more secure if there was an opt-in "I don't want to use my phone as 2FA".

Phone number authentication creates a weakness for anyone who is in a targeted attack.

A motivated attacker can easily bribe/trick a telecom employee, or if physically accessible, swipe the phone itself to read 2FA texts.



Sign up for Google's Advanced Protection Program. It's been around since 2017, and last I checked, it's the only way to fully disable the use of your phone number for authentication.

https://landing.google.com/advancedprotection/




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: