Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

No, that's easy.

People's accounts get hacked all the time. To help them recover is often a manual process, because the true owner of the account can become unclear. To be able to do that a support worker must be able to change the email address on an account, undo 2FA settings and make other changes because hackers will typically change the email address and add 2FA of their own phone as the first step in an account takeover.



But why would the support worker need to be able to post a tweet?


If you can change the owner of an account you don't need a special interface to post a tweet.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: