Hacker News new | ask | show | jobs
by dotancohen 1062 days ago
And once that happens, I then steal the target's phone.

If we're talking about deactivating someone's account via email, we are already talking about a targeted attack.

1 comments

I'm not sure how relevant that threat model is (OS level security would probably be enabled for people susceptible to be targeted in such a way. Support could advise to do it before toggling the flag, etc.), but anyway the hypothetical flag would only be about making sure the automation doesn't happen and the ticket goes to support. Support can then manually handle the rare edge case and place more burden on the person attempting to deactivate the account.