Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Make the 2FA code a one time use only then the code would be useless.


Not true. The attacker is the only one who actually uses the 2FA. The user never gets logged in.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: