frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Ask HN: When "Two-Factor Authentication" (2FA) Aren't Two

2•s3131212•6h ago
I was using my online banking service to transfer money today, and in my country the transfer requires an SMS OTP (yes, I know SMS is terrible for security). I noticed that my Mac automatically filled in the SMS OTP that was sent to my iPhone, even though my iPhone was still locked.

The idea behind SMS OTP is that it proves you "have" the device. But in this case, as long as the device is nearby, my Mac can read and use the code without me unlocking the phone. I don't even need to touch the device. So the "possession" factor doesn’t really work the way it's supposed to.

It got me thinking, are there more examples where 2FA accidentally collapses into a single factor? Or where the two factors aren’t as independent as we assume?

I find this pretty interesting and want to look more into it, but a quick search hasn't turned up much. Does anyone know if people have already written about this?

Comments

winstonwinston•56m ago
That is how it works if you have Messages sync enabled. Other MFAs are also synced on Apple devices: TOTP and Passkeys are synced via iCloud Keychain to all iPhones and Macs using the same iCloud Keychain account.

I believe google synced TOTP and Passkeys between Android devices using same google account, i did not test this though.

Obviously one can disable sync, but imo synced MFA is what most want anyway.

Ask HN: Claude Opus performance affected by time of day?

23•scaredreally•9h ago•27 comments

Ask HN: Share your personal website

895•susam•2d ago•2319 comments

Tell HN: The way I do simple data management for new prototypes

7•AndreyK1984•14h ago•5 comments

Ask HN: How can we solve the loneliness epidemic?

748•publicdebates•1d ago•1184 comments

Ask HN: How are you doing RAG locally?

391•tmaly•2d ago•151 comments

Ask HN: How have you or your firm made money with LLMs?

7•bwestergard•9h ago•7 comments

Tell HN: YouTube gave my username switzerland to a half government organization

18•faebi•14h ago•5 comments

Ask HN: What did you find out or explore today?

212•blahaj•2d ago•396 comments

At the phase 'build a startup cause I can't get hired, and maybe I'll get hired'

7•danver0•3h ago•1 comments

Ask HN: Those who quit tech, moved back home, what do you do?

12•akudha•5h ago•5 comments

Ask HN: Browser extension vs. native app for structured form filling?

2•livrasand•3h ago•0 comments

Ask HN: One IP, multiple unrealistic locations worldwide hitting my website

41•nacho-daddy•1d ago•24 comments

Ask HN: Who's Using DuckDB in Production?

3•yakkomajuri•5h ago•4 comments

Ask HN: Local media server, receive and send audio?

2•thedangler•5h ago•1 comments

Ask HN: When "Two-Factor Authentication" (2FA) Aren't Two

2•s3131212•6h ago•1 comments

Ask HN: Have you ever tried low-code tools for your work?

3•andre_fernandes•13h ago•1 comments

Ask HN: LLM Poisoning Resources

4•totallygeeky•7h ago•0 comments

Ask HN: Tips for better image generation? I need help

2•gweets•7h ago•1 comments

Why is nobody using this? Full-duplex voice streaming with Gemini Live in React

3•loffloff•7h ago•0 comments

Ask HN: What are your best purchases under $100?

76•krishadi•1d ago•217 comments

Tell HN: HP Ultra G1a Bios Freezing Issue

2•BizarroLand•8h ago•0 comments

Ask HN: Iran's 120h internet shutdown, phones back. How to stay resilient?

113•us321•3d ago•99 comments

Ask HN: Is sending a lot of requests but respecting rate limits DOSing?

2•SpyCoder77•8h ago•0 comments

Ask HN: Analogy of AI IDEs for code vs. "AI IDEs" for personal health data

2•nemath•8h ago•0 comments

Ask HN: How do you safely give LLMs SSH/DB access?

80•nico•2d ago•105 comments

Ask HN: AI music covers in 2026?

16•sexy_seedbox•1d ago•9 comments

Ask HN: What are you working on? (January 2026)

256•david927•5d ago•874 comments

Tell HN: Execution is cheap, ideas matter again

14•keepamovin•1d ago•5 comments

Ask HN: How to make spamming us uncomfortable for LinkedIn and friends?

12•zx8080•1d ago•7 comments

Ask HN: Is token-based pricing making AI harder to use in production?

2•Barathkanna•10h ago•5 comments