4 ms·
Malware can sniff one password in a similar way that malware can read your password manager's vault. So yeah, one malware and all your unique website passwords
by BlackFly 2y ago
Malware can sniff one password in a similar way that malware can read your password manager's vault. So yeah, one malware and all your unique website passwords might need to be rotated after a recovery anyways.
If the 2fa was a yubikey or some other unique made-for-purpose device, the accounts wouldn't need to be recovered, but TFA is talking about microsoft authenticator so it could very well be on the compromised device.
The most irritating thing about security is people treating it as one dimensional: more or less secure. 2FA changes security in a complex way.