Hacker News new | past | comments | ask | show | jobs | submit login

> unless that specific service had a breach

Right, and if an attacker can dump password hashes they can likely dump TOTP seeds as well. With that level of database access the attacker may be able to steal all your info from the impacted service, so talking about the password may even be a distraction since all your data is already stolen.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: