It's 2024, and this is the majority of 2FA in a nutshell:

Institution: I'm sending you a code I need you to put into this form.
Institution: Also don't give it to anyone.
Institution: Oh except me.
Institution: Oh except for these other codes which we'll send from the same shortcode but will never ask you for.
Institution: Don't get confused or hacked lol

#infosec #security
@josh Institution: The code expires ten minutes from now even though our buggy software will probably only send it in about seven minutes after you got distracted and started doing something else. No you can't have another code within 24 hours, only a hacker would want that.