Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

How is this any different than the prior situation?

Now instead of needing to trick a user into giving you their username and password, you need to trick them into giving you their username, password, and one-time token.

It's designed to address situations where the password is discovered by other parties.



The attacker would have access only for that session.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: