Comment by Zak

5 years ago

Credential stuffing is a widespread problem. Im sure everyone on HN uses a password manager and different passwords for every service, but many people don't.

It's makes a lot of sense for a high-value target like banking to require 2FA, but SMS is the worst way to do it.