Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

There was a flaw in the system that Google uses to allow the transfer of control from an account. Two-factor authentication wasn't compromised itself, but the attacker was able to bypass it to access it. That flaw, they tell us, has since been patched on their end.


Can you explain this? After the attacker reset the password of cloudfare.com email address what exactly did they do? How exactly did they login?




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: