Hacker News new | ask | show | jobs
by xur17 3620 days ago
The article links to lastpass multifactor [0] though. I agree that having multifactor enabled on the site the credentials were stolen for would block this attack.

[0] https://helpdesk.lastpass.com/multifactor-authentication-opt...

1 comments

Hm, you are right. I am not sure how LP multi-factor auth would prevent this.