3 ms·
Some forms of 2FA are unphishable. If he used Authy or SMS, where you type in a code that can be intercepted in replayed within a window, yes. If he had set up
by pabl8k 7y ago
Some forms of 2FA are unphishable. If he used Authy or SMS, where you type in a code that can be intercepted in replayed within a window, yes. If he had set up a hardware key like U2F (like a yubikey), no.
edit because I can't reply: for twitter you have to remove your phone number. I keep TOTP active as a backup, but might not if I had a highly followed account.
- dmoy 7y agoDoes twitter let you disable sms/authy fallback if you are using u2f? Many websites don't.