Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Aren't recovery codes associated with TOTP authenticator use? In this case it seems phone number was used as the second factor.


Good point. I have recovery codes saved for my account so assumed they were also generated when using SMS. SMS as 2FA really never should have been.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: