Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Mitigating password reuse is far from the only purpose of MFA. If you are using any sort of SSO or account that signs in to multiple services (I think Xbox falls into this category as a Microsoft account), then it can also protect you from an attacker who steals the login info from one place and uses it to sign in to a different service. In the case of a Microsoft account, all it would take is one decent enough phish, one app storing your email credentials improperly and accidentally leaking them, or a quickly blocked malware infection that nevertheless manages to steal your password manager’s contents, and without MFA the attacker can then log in to email, Xbox, and so on.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: