Oh, I didn't even think of it from a breach perspective. I haven't come across that anywhere, but since wf is using it, that must mean it's getting or going to become a common method. Ugh

Reply to this note

Please Login to reply.

Discussion

i refuse to use any system i know is vulnerable... that's why i have zero SMS based 2fa anymore and i avoid google authenticator... IT USES SHA1!!! fffs i'm not kidding you go read up on it, what a fucking shitshow

basic opsec

good on you

Can SHA1 be cracked in 30s? Because the key is rotated every 30s.