logoalt Hacker News

sosodevtoday at 4:47 PM2 repliesview on HN

Support requests have always been the weakest link in the security chain for big corps. I've had accounts of mine turned over with 2FA disabled by humans before. I guess we shouldn't be surprised that the LLMs are doing the same thing.

The simple fact that 2FA can be removed by low level support staff drives me mad. It defeats the whole purpose of the process.


Replies

moritzwarhiertoday at 5:28 PM

100%

Urgency.

Emotions.

It's all there, and high-stakes environments with no proper protocol are most vulnerable.

Source: used to work part-time in IT support at a hospital, by now 10+ years ago, so it was routinely requested to circumvent regulations and security protocols, even medical ones (cough Windows in ICU monitors and other medical "kiosk" PCs that should absolutely not run Windows)

show 1 reply
spullaratoday at 4:50 PM

recovery is always the weakest link in any authentication system

show 5 replies