Hacker News new | past | comments | ask | show | jobs | submit login

Just to add to my comment:

It might be confusing but that was account recovery attack.

For account recovery there is no "password" as thieves just made their own password while having victim phone number.

So phone number as a password recovery option is not secure without any additional checks. Not 2FA because with this attack there was no second factor.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: