back

by anderspitman·7y ago·view on hn ↗
I agree I'd 100% prefer something like Duo if people were already acclimated, but I think we're 5-10 years away from that reality, if we ever get there.

But I think a lot of the risks you're talking about are mitigated by having the initial link/code expire in 5 minutes. Not completely removed, but mitigated. The risk profile isn't great but it's not any worse than an email-based password recovery flow.

> I remember someone claiming an email security appliance vendor was "brute forcing" them,turns out they mass-emailed something with their URL in it and the appliances at different companies were detonating the URLs in different virtual environments to see if they cause anomalous behavior.

This is interesting. That might make prevent me from being able to make the codes single-use, which greatly increases the risk.

1 comments
SMS is more secure than email. I challenge anyone to prove me wrong.