Skip to content

Comment on 6 digit OTP for Two Factor Auth (2FA) is brute-forceable in 3 days

Comments

I feel like the service has larger problems if they're allowing you 10 requests a second for 3 days...

Not to mention not warning the user that their account is being brute forced.

My recent experience was to get locked out of an account for a few incorrect password attempts. I was the source, had forgotten I changed it or something, the incorrect attempts were a while ago and I don't remember what I was thinking at the time. Required hours on hold waiting for an operator and dancing through stupid hoops (that make more sense to me as audit ass covering than actual security).

Huge pain in the ass.

Do you use a password manager? You should.

Sure. Doesn't mean I never fuck up.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.