logoalt Hacker News

croteyesterday at 10:08 PM0 repliesview on HN

Yeah, but it's an order-of-magnitude more complicated. It's no longer "click a link and fill in your creds on a legit-looking website", it turns into "hack someone's email, request a password reset, wait the mandatory 24 hours, do a social attack on the provider to pull off a sim swap, and fill in the 2FA code".

> Your master password to your cloud PW manager's vault is also phishable

... which is why all sensible cloud vaults have a separate enrollment key, requiring an explicit action to grant a new device access.