Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

MFA isn't solely about "the user had poor security posture and can't be trusted". It's about what happens even if the user's info is leaked by a information breach of a service. I.e. "having the login info for the service isn't enough, the user must be notified and approve of the login via a separate factor".

That's why MFA is referred to as defense-in-depth rather than being a better password.



Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: