Quote Originally Posted by Keres View Post
It's not really that hard:

- If you have a keylogger
- If you use the same user ID you use in other online services

But even in that case, as the OP said, setting up OTP protection on your account will go a long way to preventing unauthorized access.
Actually, if he got keylogged he'd be just as easily session hijacked to get a OTP since they don't immediately decay to allow users time to input them.