Hacker News new | ask | show | jobs
by hackernewslol 2037 days ago
If the hacker has direct DB access (as they so often do), then rate limits don't really matter (nor does 2fa, they can just get the secret right out of the database and use that to generate their own codes).