TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Why Hasn't Hacker News Implemented TOTP for 2FA Yet?

1 点作者 mbix772 个月前
Hey HN,<p>Been thinking about account security and noticed that Hacker News still doesn&#x27;t offer any form of 2FA (Two-Factor Authentication). Given the tech-savvy community here, it seems surprising that we don&#x27;t have this extra layer of security.<p>TOTP (Time-based One-Time Password) would be a great option to start with, considering its balance of security and convenience.<p>So, I&#x27;m curious:<p><pre><code> * What&#x27;s the hold-up with implementing 2FA, specifically TOTP? Any technical hurdles or other considerations? * How important is 2FA to the HN community? </code></pre> Seems like a no-brainer to add 2FA and beef up our account security. Thoughts?

4 条评论

freediver2 个月前
Low stakes and friendly moderators you can email in case of trouble?
almosthere2 个月前
what is being &quot;secured&quot;. Is there a hacker news bank I don&#x27;t know about?
anenefan2 个月前
Any forum type site that needs one time passwords or 2FA is obviously too secretive an area for the like of myself to be posting.
LinuxBender2 个月前
I would honestly expect the HN crowd to be using long complex passwords. That&#x27;s probably sufficient for this type of site. I guess only dang could say if HN has been having challenges with account take-overs. I never hear about it. I would not mind having the option to restrict my login to a CIDR block however. I am personally not a fan of adding third party authentication unless it is entirely self hosted and the code is reviewed by teams like NCC.<p>For banks and some DNS registrars I use IP restrictions in addition to whatever 2FA <i>usually SMS</i> they support along with challenge questions. Additionally for banks I make most of my accounts read-only from the internet. IP restrictions are a feature their support team dislike as many people think they have a static IP when they do not.