Hacker News new | ask | show | jobs
by newZWhoDis 905 days ago
LTT found out the hard way, their attacker had a session token for an employee and changing everyone’s passwords didn’t lock the attacker out.