Hacker News new | ask | show | jobs
by charleyma 2895 days ago
Username + password is a huge attack vector, especially for services where users signup and eventually stop using or forget. I wish there was some obligation to reset password or require some form of MFA for applications that experience no usage on my account (especially if the service typically encourages continuous usage)...
1 comments

What does this have to do with this attack? Timehop does not store any passwords, just access tokens.