Hacker News new | ask | show | jobs
by ksaitor 2059 days ago
Hi HN, the author of the article here.

Can someone explain how Telegram 2FA, Yahoo 2FA and Apple 2FA were bypassed?

Especially Apple 2FA - I received a 2FA call from Apple, picked it up, and the attacker logged in right after.

Please note, this was not a (typical) SIM swap. I was still receiving SMS and calls during the attack.

p.s. thanks for all the comments!

1 comments

Did you have more than one trusted number for Apple MFA? Trusted devices you don’t control?
Had only one number. All trusted devices were under my control.