Hacker News new | ask | show | jobs
by arnarbi 4267 days ago
Re 1: If a.com is hacked, only a.com's OTP seeds are compromised. b.com should (hopefully) use different seeds, so 2FA still prevents someone from logging in.
1 comments

Yes you are right - I was thinking about the case where only a.com uses 2FA, not b.com