Skip to content

Comment on How Apple and Amazon Security Flaws Led to My Epic Hackingparent

Comments

If you didn't revoke the application-specific password. And you should be revoking them when you're no longer using them.

If you weren't using application specific passwords, of course, it would have been your actual Google password in that Pidgin config.

It's a little disappointing that the app-specific password isn't more secure, but it's certainly not less secure than foregoing them.

App-specific passwords are bypasses of 2-factor auth. Use them selectively and with care, revoke ones you're not using anymore. And replace them from time to time.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.