Hacker News new | ask | show | jobs
by wongarsu 483 days ago
But if somebody compromised their internal infrastructure they could push out malicious updates to both the Authenticator and the clients of the password manager (most likely the browser extension), compromising both security factors at once