• shortwavesurfer@lemmy.zip
    link
    fedilink
    English
    arrow-up
    0
    ·
    edit-2
    19 days ago

    Idiot. Why did they not run those searches over the tor network to anonymize themselves? That is quite frankly stupid. And the fact that the SEC was using SMS-based two-factor authentication is also stupid. One time pads or bust motherfuckers.

        • InverseParallax@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          19 days ago

          They’re actually not, they’re algorithmically derived state machines, most are public key hashes of secrets concatenated to the current time in seconds from the epoch.

          Ideally they would be otp, but that would also be obnoxious.