1 comment

[ 6.6 ms ] story [ 24.5 ms ] thread
If I understood this correctly, two factor authentication was irrelevant.

Whoever did this just forged the cookies and had full webmail access regardless of any authentication method.