Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Have you read the article ? the 2 factor authentication wasn't compromised, it was mostly a social engineering attack. Even if it was the 2 factor authentication that was compromised, how would this be Jeff's fault ?


There was a flaw in the system that Google uses to allow the transfer of control from an account. Two-factor authentication wasn't compromised itself, but the attacker was able to bypass it to access it. That flaw, they tell us, has since been patched on their end.


Can you explain this? After the attacker reset the password of cloudfare.com email address what exactly did they do? How exactly did they login?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: