Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That's assuming your attacker already has your password, or the service allows SMS password reset. (thus negating the second factor. Essentially SMS becomes the only factor.)


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: