Hacker News new | ask | show | jobs
by umvi 2479 days ago
2FA doesn't guarantee this incident would not have taken place.

If it's not hardware-based (i.e. Yubikey), you can still spearphish people into putting their username, password, and 2FA token into a honeypot page which would give the attacker a window of unauthorized access.