logoalt Hacker News

gregoriolyesterday at 10:23 AM4 repliesview on HN

2FA is more secure than 1FA even if that one has a high security level


Replies

nixpulvisyesterday at 11:12 AM

To be clear. Proper 2FA, via something like a smartcard or any truly external device is still much more secure. You could have one of those factors be a passkey, that's fine, and may be a good idea.

But there are UX issues with passkeys as well, that aren't all well addressed. My biggest gripe is that there is often no way to migrate from one passkey provider to another, though apparently there may be a standard for this in the works?

Genboxyesterday at 10:43 AM

Are you saying that two weak factors are more secure than one strong factor?

show 2 replies
PunchyHamsteryesterday at 10:31 AM

if 2fa is "use the second factor that's on same device as first factor" (like when using phone apps in many cases, password + 2fa from email/sms/authenticator app on same device), I disagree.

show 1 reply
JasonADruryyesterday at 10:51 AM

Nonsense, depends entirely on the value of the authentication factor.