> (usually, when a password change occurs, it logs out the user of all platforms).
That is what seems to be broken by this attack. You are not properly logged out when all sessions are closed, and you can manage to login without knowing the current password.
No, it does not break 2FA. No, it does not work if you have 2FA enabled.
That is what seems to be broken by this attack. You are not properly logged out when all sessions are closed, and you can manage to login without knowing the current password.
No, it does not break 2FA. No, it does not work if you have 2FA enabled.