Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Wouldn't two factor make this irrelevant?


A state actor wouldn't even break a sweat getting around 2FA, individually or at scale, if the 2nd factor involves SMS (or the phone system in general) (which, for 99% percent of the 1% of people using it, it currently does):

https://en.wikipedia.org/wiki/Dishfire

It's not even out of the question for malicious private actors who don't have total control over the whole system:

https://krebsonsecurity.com/2016/09/the-limits-of-sms-for-2-...


No, because if you refuse to help them access your account, they will detain or turn you back.


Yes, those people will simply be denied entry.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: