> there will be some other service that doesn’t do this so the user is still vulnerable to credential stuffing - just not on your service.
"If they don't practice good security, why should we?"
The other points would have been stronger if he'd just admit that there is this small advantage to sms2fa. As is, he's making a ridiculous argument in an attempt to make the issue wholly black and white.
"If they don't practice good security, why should we?"
The other points would have been stronger if he'd just admit that there is this small advantage to sms2fa. As is, he's making a ridiculous argument in an attempt to make the issue wholly black and white.