Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>is the 2nd factor required

Email is not a factor in authentication, it’s a user identifier. There is a huge difference between the two. Requiring users to also provide their first name is also not a factor.

Email is just a worse version of the same factor in a login. They are both just “something you know” only email is even worse because it’s something everyone who knows you knows.

Just to drive the point home, if a website asks you to set three passwords that it asks you for on each login, that’s not 3-factor or even 2-factor authentication. They are all just part of the “something you know” factor.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: