Hwee-Boon Yar
PRO
@hboon
stacknaut.com
myog.social
theblue.social
Write software TypeScript (web) + Swift
hboon.com/about
So the hypothesis is that the attacker reset 2fa and then reset your password? (I wasn't sure you were saying they let you, or possibly that they let the attacker reset it)
yup - they let the attacker do it. all you need is the email address and/or phone number. if this information is already public - well, you're hosed @hboon
you should see the email i got when it was time to ask for a reset - maybe you just need to be convincing. aka social engineering
But third party apps with OAuth access can't sign into X website/apps to change your password/email, right?
You don't. But you try to do load more (again, as a habit, not via ad-hoc sheer force of will) if you reasonably can. The critical part is to keep going at it.
It's OpenClaw now 🤣