Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

They can re-activate the keys they automatically purged from my account, I still have their associated private keys. My github profile also has detailed information in its bio section including my past employer and links to my various social media/website. They could simply validate my ownership of one of those accounts etc.


The social media websites could have been hacked by some attacker, the private keys could have been obtained as well. Or put there by an attacker that is now locked out by 2FA.

The entire point of 2FA is that it's a second factor and no way around it without a second factor that is verifiable without doubt.


Nope. Many 2FA setups have a way to workaround the second factor if it’s missing. Recovery codes, emails to secondary addresses, faxing an ID, etc etc.


If you can social engineer yourself around 2FA it's not a proper 2FA setup.


So they could hack your other social media accounts possibly also with 2fa enabled but not be able to steal your back up codes smfh


Yeah seems simple to ask you to sign message with your key to prove its you!




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: