Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> In many cases they are already syncing a copy of your passwords.

No, that gets them the full way there. They have your 2FA codes, and if you use Chrome and opt into it syncing passwords for you (passwords.google.com), this gives them both pieces of the puzzle.



If you use chrome, they could just download your cookies if they really wanted to.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: