Comment by pants2
3 months ago
That still requires stealing your 2FA again. In this attack they compromised a one-time authenticator code, they'd have to do it a second time in a row, and the user would be looking at a legitimate "new signing key added" email alongside it.
No comments yet
Contribute on Hacker News ↗