Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> How is it possible to have compromised password but not compromised the second factor?

Server-side (assuming weak password storage or weak in-transit encryption) or phishing (more advanced phishers may get the codes too but only single instance of the code, not the base key).

> What is stopping webmasters from using 100FA?

The users would hunt them down and beat them mercilessly?





So 2FA is a protection against the server's admin? Not even the user's protection but the webmaster's one?



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: