Hacker News new | ask | show | jobs
by hayd 3800 days ago
There's no reason to assume he wasn't using 2FA. The title says "backdoor" and that's the point: they didn't verify identity... they asked for name, email and a nearby address.
2 comments

> Actually, I do have 2FA enabled on my account. But I don't think I had it enabled at the time for the very first attack.

https://news.ycombinator.com/item?id=10965111

I don't think he was using 2FA; if he was, Amazon CS would not have given him the information (or at least should not have, based on their own policies): https://www.amazon.com/gp/help/customer/display.html?nodeId=....