Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Interesting but far from an account compromise on it's own. You still need to know the user's password in the first place and, I believe, you can't repeat the attack once they change their password. So if they change their password a second time or enable MFA themselves you're blocked permanently. So it allows for a existing attack to be prolonged one time and possibly makes it harder for a user to realize they're still compromised.

I can see some value in a targeted attack on an individual although only if they don't respond by turning on MFA themselves.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: