Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

How is that social engineering? It doesn't seem like human behavior played any role in this at all. The hacker interacted only with automated systems.

This is a security bug that was exploited. It should not be possible to reset a password without the 2-factor auth code, period. If that is possible, then that the 2 factor auth is broken.



When people say 2-factor auth code is broken, it implies there was an issue with the 2-factor authentication code itself. That would mean things like RSA and other Token based authentication might be at risk. So no 2-factor auth is not broken. Authentication in Google is broken.

-disclaimer: I am the founder of Authy.com.


Well of course the concept of 2-factor auth is still sound. No inherent flaws in the math or the theory. But this particular implementation is quite broken.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: