Comment on LinkedIn user data leaked: Database shows emails, profile data, phones, full names, and more confidential info.

<- View Parent
kungen@feddit.nu ⁨10⁩ ⁨months⁩ ago

well with PGP, the header is unencrypted

Is there a single large company that even sends PGP email?

logging into example.com with the user’s email and that 2fa code is going to be a breeze

Sure, IF 1. you already have the user’s password, and 2. a new code wouldn’t be required/the previous code invalidated when initiating a new login session?

Like, I’m not saying that 2FA codes via email is secure, but you’re implying that they are making a security hole via this - which I don’t see.

source
Sort:hotnewtop