3 ms·
2FA was probably the most important improvement to security in a long time. It seems to be the only thing that kept attackers out when everything else has been
by SilverRed 5y ago
2FA was probably the most important improvement to security in a long time. It seems to be the only thing that kept attackers out when everything else has been exposed.
- judge2020 5y agoThis only helps for credential stuffing attacks that use passwords from other database leaks, though - chances are the 2fa shared secrets are on the same row as the user's (maybe clear text[0]) password and can be easily used to get in despite 2fa. 0: https://www.pcmag.com/news/t-mobile-austria-is-ok-with-storing-passwords-partly-in-clear-text https://www.pcmag.com/news/t-mobile-austria-is-ok-with-stori...
- SilverRed 5y agoIf the attacker has direct access to the system, there is not a lot you can do to stop them getting in to that particular system. The main problem imo is that people would use the same password on secure and non secure services so some random forum login ends up with their icloud details exposed. Which 2FA solved.