Skip to content

Comment on You don’t need SMS-2FAparent

Comments

There are security dimensions on which TOTP is worse. It's plausible for the SMS code to contain enough information about the login attempt to make the user realize they're being phished.

"Are you trying to log in from Ukraine? If yes, the code is 123456."

"Bank tranfer of 10000 EUR to account XYZ: verification code 987654"

TOTP obviously can't do this.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.