back

by seanieb·1y ago·view on hn ↗
TLDR; Microsoft didn’t have rate-limiting on their TOTP MFA if you opened different tabs. Allowing attackers enough guesses to get the users MFA code.