Hacker News with Generative AI: Multi-Factor Authentication

Why MFA is getting easer to bypass and what to do about it (arstechnica.com)
An entire cottage industry has formed around phishing attacks that bypass some of the most common forms of multifactor authentication (MFA) and allow even non-technical users to quickly create sites that defeat the protections against account takeovers.
The least secure TOTP code possible (shkspr.mobi)
If you use Multi-Factor Authentication, you'll be well used to scanning in QR codes which allow you to share a secret code with a website. These are known as Time-based One Time Passwords (TOTP0).
Change Healthcare hackers used stolen credentials and no MFA, says UHG CEO (techcrunch.com)