utxo the webmaster ๐งโ๐ป
· 6w
Btcpayserver exploit explained:
The old check only refused Basic auth if the user had FIDO2 credentials (a hardware security key). If you secured your account with TOTP (Google Authenticator etc.), ...
So the attacker still had to obtain username +password?