Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think the parent is theorizing that they could emulate someone logging in through their own headless browser to see if the credentials are valid, then if they are and the account has 2FA, they could trigger the SMS.


Exactly!

I'd assume there's CSRF on the login page, hence why I said: "hope ... Google notices the source IP or user-agent of the attacker"




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: