Hacker News new | ask | show | jobs
by gcr 4919 days ago
If I want to prevent you from accessing your account for at least 24 hours, couldn't I just try to log in as you and intentionally enter an incorrect PIN thrice?

Am I misunderstanding something?

1 comments

Yes, you have to have the phone, but this is still possible.
Ah, OK. Better than a remote attack for sure.