Hacker News new | ask | show | jobs
by bakatubas 1890 days ago
Or mandate 2FA and password managers.
1 comments

Even that is often not enough: sessions are long lived and very often stealing a cookie is all the attacker needs.