Earlier quoted context omitted.
Fat fingers happen, so I could see allowing maybe 3 attempts from a usability and convenience standpoint. Beyond that, definitely should regenerate / resend. This is to confirm you own that phone number. It's not hard to get another
Yeah for sure, a few attempts isn't a problem IMO, even only say 6 digits there's too many permutations. > I have used 1000 different machines (to achieve concurrency easily) and IPs to send 200k requests (that’s 20 percent of total one million probability) in my tests. I'm just surprised nobody looked at a dashboard and said "huh this account is getting 200k requests", surely that should be raising red flags?
I think my bank uses letter is text-based 2FA.