Hacker News new | ask | show | jobs
by testvox 2886 days ago
Yeah that's why codes don't make for a good second factor. You should use something like Fido or a client cert such that a MitM can't continue to impersonate the client.