Hacker News new | ask | show | jobs
by hn_throwaway_99 2052 days ago
That seems along the lines of "I can just turn off the ability to log in to prevent account hacking!" level of security thinking.
2 comments

If your choices are "disable all logins" or "anybody can log into my bank account and make whatever transfers they want", the correct choice is the former. (Obviously I would prefer a third option, where the company actually fixed the login bug sometime during the 104-day lead-up, but that's not the point.)
For some accounts you do exactly that if you have to.