Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Or just let people to disable 2FA. That's simplest and easiest solution. Slap a red warning label if you need to.



For better or worse, I can’t set my password to be “password” or any other number of weak words, and also need a number and symbol. Same principle in practice here.


It's realistic to expect people to remember a difficult password eventually. It's not realistic to expect them to recover the SIM card from a phone that was stolen from them in the middle of the night and pawned for drugs or broken down into parts.


Why would a strong password and needing an entirely different communication channel be the same thing? That's like saying walking to work and needing to drive a car to work are the same thing.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: