Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Your device, as well as another device, and yet another - are all independent "something you have" factors from "the password you know". And adding new device can be restricted via 2FA old device

And I've addressed the backup codes - that's the alternative mechanism that's no better than the sync. Also, backup codes are not 2FA, so if you're so strict about 2FA you don't even allow sync, then you can't have them, thus permanent loss



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: