Live data from Hacker News

PayPal adds insecure SMS based login that circumvents 2FA. Ignores concerns

paypal-community.com

1–2 of 2 posts

Re: PayPal adds insecure SMS based login that circumvents 2FA. Ignores concerns

#2
PayPal recently added a "Log in with a one-time code" feature that circumvents the username/password and any 2FA on the account. Instead, a 6 digit code is sent via SMS to the primary phone number linked to the email address. Given the prevalence of SIM Hijacking attacks, this seems extremely insecure.