you are viewing a single comment's thread
view the rest of the comments
[–] 20 points 2 months ago* (2 children)

And because SMS 2FA is actually opening a common attack vector. I have yet to find a credit union I qualify for that uses TOTP or Yibikey.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 5 points 2 months ago

    That still requires getting personal information about the user, which is often enough without 2FA. 2FA still makes it more secure than not having it. It's still a vulnerable step though, so users should be aware of that.

  • source
  • parent