Hacker News new | past | comments | ask | show | jobs | submit login

Valid TOTPs should still only work once when implemented well. And yes it's not easy to exploit. The idea is something like a malware could sit and intercept a successful login then initiate its own session by re-using the MFA code before it expires.



Yeah, but malware in that position can also just steal your session cookie.


Malware can also just steal your session cookie.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: