Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> and information relating to Mobile and Dial-In Authenticators were also accessed.

I don't know a ton about 2 factor auth implementation details, but I'm assuming that if you were able to access the serial # or whatever is used to uniquely identify an authenticator, you could generate valid tokens, essentially rendering the 2 factor auth useless?

If so, and if they were also able to access information about the key fob authenticators, that could be messy. Hopefully that isn't the case.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: