Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The fact that they immediately enforced MFA after the breach shows they know exactly how culpable they are.


Yeah, that's a pretty dumb movie on their part to immediately mitigate the attack and show the whole world it was possible the whole time and it was via an industry accepted best practice.

Why people don't get that TOTP is just "strong unique password" you can enforce from the service provider side is beyond me.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: