Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You could use https://mbasic.facebook.com/ which doesn't use any JavaScript (there is actually no script tags in the page source).


I wonder how soon they'll try to plug that hole with something like requiring 2FA for each login.


It's not hard to automate 2FA. Especially if it supports offline google-style 2FA. But SMS are doable too.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: