(no title)
0xfeba | 6 months ago
Was about to post just this. This is the flow they use for account recovery so it's the weakest link in the chain anyway.
0xfeba | 6 months ago
Was about to post just this. This is the flow they use for account recovery so it's the weakest link in the chain anyway.
ThunderSizzle|6 months ago
Since this is about the human accidentally getting tricked to give a code to a malicious actor, I do think that workflow abuses humans being overtired by too many factors of auth by too many different services. I just want to login and get my thing done, but now I have to spend time waiting on email, etc.