11 ms·
Lack of 2FA for the AWS access ? Sure. It might have prevented the attack. The attacker had access to the whole database. Which meant he could alter the 2FA se
by aneutron 6y ago
Lack of 2FA for the AWS access ? Sure. It might have prevented the attack.
The attacker had access to the whole database. Which meant he could alter the 2FA seed. So it wouldn't have mattered much.
- dathinab 6y agoThey seem to have gained access through getting secrets from developers as far as I understood it. So with 2FA they would have had a much harder time to gain access to the database. The part of changing the seed only matters for customers of the hacked company but is (as far as I can tell) unrelated to them gaining access.