Hacker News new | ask | show | jobs
by marshray 4855 days ago
I think the "still" was meant to refer to "after the addition of the 2nd factor to the auth process" rather than "after the fix to the vulnerability described here".

It's making the case that this does represent a "real" vulnerability, even if certain aspects of the behavior were understood and expected by the system designers.

1 comments

Yeah after re-reading I think you are correct. And yes, I certainly agree that it was a real vulnerability!