Framing MFA as "someone had this factor at this moment" is the right correction, because it says nothing about the session token that lives for hours afterward. Most account takeovers I read about now skip the prompt entirely: token theft, push fatigue approvals, or a helpdesk reset that re-enrolls a new factor. Phishing-resistant factors like passkeys close the first gap, but recovery and re-enrollment stay the soft spot. Which control do you think gets the most underinvestment: session binding, or verification at the helpdesk reset step?
iin1005h0728
Framing MFA as "someone had this factor at this moment" is the right correction, because it says nothing about the session token that lives for hours afterward. Most account takeovers I read about now skip the prompt entirely: token theft, push fatigue approvals, or a helpdesk reset that re-enrolls a new factor. Phishing-resistant factors like passkeys close the first gap, but recovery and re-enrollment stay the soft spot. Which control do you think gets the most underinvestment: session binding, or verification at the helpdesk reset step?
iin1005h0728