Hacker News new | ask | show | jobs
by SpaethCo 2887 days ago
They got around 2FA over SMS because a number of services like GMail offered password reset via SMS as well as 2FA over SMS.

It was the password reset process that was the most vulnerable, and strangely the part that kept getting glossed over when people reported on the takeover incidents.