Hacker News new | ask | show | jobs
by cortesoft 3892 days ago
Even 2FA will have some mechanism for resetting the password without the second factor, because people lose their 2FA device (usually a phone) all the time. There has to be a way to recover from losing your 2FA device - given how easily the social engineering was shown to be here, I doubt that would help much.