From SMS OTP to Passkeys: Your Real Weakness Is the Recovery Path

AryHHAry · x · 2026-09-19

A systematic thread on account authentication security, answering which is better among SMS OTP, authenticator apps, and passkeys:

Key takeaway: the chain is only as strong as its recovery path — if "lost device" still falls back to SMS, you haven't left SMS 2FA. Full references included.

Original post →

More from Safety

Safety channel →