Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Session jacking can also allow disabling MFA unless sites are careful to re-verify the MFA before doing so. Or before changing the password or adding additional tokens / generating backup codes.

Security is hard. And features make it porous.



Yeah, a site needs to issue an MFA challenge to any MFA change attempt.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: