Hacker News new | ask | show | jobs
by arubania2 1525 days ago
Well isn’t that a problem in itself then?

The way I understand it, the password database should only contain the passwords; then if someone got access to it (or your email app, same thing, as they would just do a password reset) 2FA would still protect you.