Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

By "forward" you mean that we ask people to submit a 2FA code during login? YMMV, but I would characterize that as "supporting users who have 2FA enabled" rather than "getting around 2FA". Like I said, I'm looking forward to a world where we don't have to ask for credentials at all, but in the current world, we either support 2FA or we don't, and if we didn't, many people would probably turn off 2FA altogether. At a number of institutions, we actually add a layer of 2FA protection and require a SMS-based code if the institution doesn't prompt the user with its own 2FA.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: