logoalt Hacker News

tialaramexyesterday at 8:11 AM0 repliesview on HN

That's true, but in terms of system design you definitely should ask to see the proof of identity again during unusual transactions and not just that bearer token - for example attempts to add or remove 2FA should need that extra step, as well as say high value financial transactions or irreversible system changes.