Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Me too. For me it is because I moved country, and now my 2FA SMS won't work because my number changed. And there is no way around it, no 2FA no account.

I mean, yes, I understand security blah blah. But if I can send you a scan of my passport, which shows the same me as in most of the photos, surely that is an exception? And if I can reply to the same [email protected] too? But no, there is no way I can get to a human.



I am a bit torn on this one. On one hand it makes sense that you shouldn't lose the account, on the other it opens 2FA up to social engineering.

Recently I have been a lot more careful storing provided one time codes or the original QR code to prevent running into this.


Best practice is to never use 2FA SMS


Agreed, but it was the best option available at the time.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: