Hacker News with Generative AI: Two-Factor Authentication

Bitwarden is turning 2FA on by default for new devices (bitwarden.com)
To keep your account safe and secure, in February 2025, Bitwarden will require additional verification for users who do not use two-step login.
Yubico Issues Security Advisory as 2FA Bypass Vulnerability Confirmed (forbes.com)
Two-factor authentication has increasingly become a security essential over recent years, so when news of anything that can bypass those 2FA protections breaks, it’s not something you can ignore.
Why does storing 2FA codes in your password manager make sense? (andygrunwald.com)
Why does storing two-factor authentication codes in your password manager make sense?
Tell HN: 2FA code for Google account gone after Google Authenticator update (ycombinator.com)
After recent update, where Google added accounts support to yet another of their apps, I am no longer getting 2FA code for my Google Account. Only dashes are displayed and clicking on it shows very terse error message: "Could not generate code for this account. Try removing it from Authenticator and setting it up...". Of course I opted out of using account in Authenticator, as my phone is connected to different Google account.
CISA: Do not use SMS as a second factor for authentication [pdf] (cisa.gov)
Tell HN: China has all your SMS 2FA (ycombinator.com)
It occurred to me as I was trying to log into a financial website that the default 2FA method was still SMS.
Ask HN: AWS registering MFA will be required in 29 days (ycombinator.com)
When signing into our AWS console this morning we noticed this security popup - "Registering MFA will be required in 29 days".
Tell HN: Twilio quietly removes Authy iOS app from Mac App Store, stops updates (ycombinator.com)
Authy, a software application that provides two-factor authentication codes for logging into online accounts, previously discontinued its desktop app for MacOS and Windows in March 2024.
Tell HN: GitHub locked me out for not using 2FA (ycombinator.com)
Tell HN: You can add a 2FA account to multiple authenticator apps (ycombinator.com)
Never enable 2FA for accounts that you actually care about (2023) (benwilber.github.io)
The Sad State of Two-Factor Authentication in U.S. Banking (2020) (medium.com)
Loss of popular 2FA tool puts security-minded GrapheneOS in a paradox (arstechnica.com)
Second factor SMS: Worse than its reputation (ccc.de)
Ente Auth: open-source Authy alternative for 2FA (ente.io)
Show HN: Faktor – The missing 2FA code autocomplete for Chrome (getfaktor.com)
I can't use my number pad for 2FA codes (shkspr.mobi)
Roku makes 2FA mandatory for all after nearly 600K accounts pwned (theregister.com)