5 ms·
If you're already logged in to a Twitter account you can deactivate 2FA by disabling the account (aka deleting with a 30 day window) and then re-enabling the ac
by aahhahahaaa 6y ago
If you're already logged in to a Twitter account you can deactivate 2FA by disabling the account (aka deleting with a 30 day window) and then re-enabling the account.
- jobigoud 6y agoYou don't need 2FA to deactivate 2FA? That seems like a big flaw.
- senorjazz 6y agotwitter says hello
- bonestamp2 6y agoYup. The interesting thing is that this 2FA exploit was posted to hacker news two days before the twitter hack. It's possible someone seized the opportunity before it was fixed.
- dx034 6y agoDo you have a link to that? Didn't see it here on HN.
- bonestamp2 6y agoMy apologies, perhaps my memory was failing me. I can't find what I was thinking of and may have been incorrectly remembering this as twitter instead of google: https://news.ycombinator.com/item?id=23792767 https://news.ycombinator.com/item?id=23792767