Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Unless my mom's knitting forum also is an online trading platform, why do they need two factor auth? And how likely is it that their software of choice doesn't have a Twilio plugin?


Because your mom probably uses the same password on her knitting forum as she does for her bank website or email or ...


The solution to that is not to add two-factor auth to the forum but to fix the problem at its source, with a password manager or something like that.


That's not something the forum can control, though, is it? Nor anyone else who's the target audience for Authy, for that matter.


Of course the forum can't control that and neither can your bank, but out of the two, only the bank should care and implement two-factor auth. It doesn't matter if your knitting forum account is hacked into, so two-factor auth is overkill.

Now, sure the password on that knitting forum might be the same as your bank online account. But the point is that only websites where your account is sensitive needs to add two-factor authentication.

I should have phrased my comment above another way: the solution to password re-use is not to add two-factor auth to a knitting forum, but to add it to the bank website, email provider, etc. anywhere your account's safety matters.

(I was thinking more from the point of view of the user: if they start to get worried about their accounts getting hacked, two-factor auth on the forum is not the solution, a password manager is)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: