Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Email is much worse than SMS.


It could be better if the sender's SMTP server forced the use of TLS. Most emails are now sent encrypted but it isn't usually enforced.

If your control your own receiving server then it would be hard for someone to intercept the message.


That's not why its bad.

Its bad because 85% of the usecase of 2fa is people using bad passwords. If you use a bad password in one place, you probably are also doing so on your email.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: