That still requires getting personal information about the user, which is often enough without 2FA. 2FA still makes it more secure than not having it. It's still a vulnerable step though, so users should be aware of that.
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments