On Friday, a hacker logged into the Boing Boing website using a staff member's credentials, and installed code that allowed them to redirect site visitors to a malicious webpage

@gcluley lol "Even two-factor authentication ... can be compromised on the user's end" but notable by its absence, we can assume "but we weren't even using 2FA for the admins" ...

