|
|
|
|
|
by not_that_noob
2969 days ago
|
|
They might call in and say they lost their token, and a competent attacker will usually have all the necessary info. Happens all the time with credit card fraud. Sure, you can notify the target that a credential was reissued, but that happens with credit cards too, and most of the time people don’t pay attention. About 15% of the user population really cares about security and will take the right precautions. It’s the other 85% that are soft targets that keep attackers in business. |
|