Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I got caught out as I had no longer access to the old phone number that was now used to send 2FA text.


oh dang that's not good. I've had the same phone number since 2006 so I didn't really think about it


But the phone number you have is not 100% in your control. I had AT&T flub something and I lost my number and they assigned me a new one (I was chanting my plan just after they did some merging with someone). Granted its unlikely but I would still use defense in depth and not have password reset be my only login method.


Thats totally fair and really scary since so many services think 2fa means texting or calling a phone number (my bank for example)


It's also why I always opt for 2FA that's within my control: a security key, TOTP, or an email address on a domain I own. That last one is the weakest, since I own the domain as long the registrar says I do but it's better than a corporation I can't get support from if my email account is locked for any reason.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: