Hacker News new | ask | show | jobs
by howlgarnish 1971 days ago
Fake 2FA works if it's stateless, eg entering a code from Authy or a physical token.

However, stateful 2FA like sending an SMS to your phone, or popping up a notification on your banking app is much harder to spoof, and would have protected the user here.