Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That still requires stealing your 2FA again. In this attack they compromised a one-time authenticator code, they'd have to do it a second time in a row, and the user would be looking at a legitimate "new signing key added" email alongside it.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: