| ▲ | crote 2 days ago | |
Yeah, but it's an order-of-magnitude more complicated. It's no longer "click a link and fill in your creds on a legit-looking website", it turns into "hack someone's email, request a password reset, wait the mandatory 24 hours, do a social attack on the provider to pull off a sim swap, and fill in the 2FA code". > Your master password to your cloud PW manager's vault is also phishable ... which is why all sensible cloud vaults have a separate enrollment key, requiring an explicit action to grant a new device access. | ||