3 ms·
Likely in the sense that the attacker cannot login into your account using the stolen credentials, as the second factor would not be in their possession.
by johnl1479 10y ago
Likely in the sense that the attacker cannot login into your account using the stolen credentials, as the second factor would not be in their possession.
- xur17 10y agoThe article links to lastpass multifactor [0] though. I agree that having multifactor enabled on the site the credentials were stolen for would block this attack. [0] https://helpdesk.lastpass.com/multifactor-authentication-options/ https://helpdesk.lastpass.com/multifactor-authentication-opt...
- johnl1479 10y agoHm, you are right. I am not sure how LP multi-factor auth would prevent this.