b) Using email as a second authentication factor is plain dumb! Email is the first thing an attacker targets. Email is NO more a suitable MFA channel than SMS. In fact *less* so than SMS.

Comments