3 ms·
No, it's not. A username is rarely a secret used for anthentication. In this case it seems the user got tricked into giving away a password reset code given ove
by NightlyDev 6y ago
No, it's not. A username is rarely a secret used for anthentication. In this case it seems the user got tricked into giving away a password reset code given over SMS. So the first factor(password) was skipped. If an SMS code and the password would have been needed then it would be 2 factors.
SSN is alsp a stupidly bad usage as an authentication factor. A lot of people have access to it, it's not unique to the service and you can't just change it whenever you want.