logoalt Hacker News

OutOfHereyesterday at 10:35 PM2 repliesview on HN

It was not declared whether 2FA was enabled on the account or not. I will assume that it wasn't enabled.


Replies

mookyesterday at 10:44 PM

Hmm, I don't know the area well; why would 2FA have been relevant here? From the (unverified) story, the account was administratively handed over via support; there was no indication from any party that the account was hacked. So 2FA prompts would never be part of the picture.

john_strinlaiyesterday at 10:50 PM

a support-initiated reset and transfer would bypass 2fa