Over 5,300 GitLab servers exposed to zero-click account takeover attacks

Nemeski@lemm.ee to Technology@lemmy.world – 353 points –
bleepingcomputer.com
48

You are viewing a single comment

Or just make it clear your account is gone if you lose your passkey, so have a second key for backup or learn a hard lesson.

Yeah, good luck with that. You can tell someone "if you lose this token, all data are unrecoverable", they'll reply with "ok, got it!" and about two and a half second later call you saying "Hey I lost my token can you recover my data?".

Hence the "hard lesson" part. A lot of us tech-focused people learned the same lesson with our document backup systems. You lose some important documents, then you realize you really should backup your stuff. All I hope is these people learn the lesson earlier in life before the consequences become more and more severe.