Which attack classes stop working?

Created by Fu Yi, Modified on Tue, 28 Jul at 4:15 PM by Fu Yi

  • Phishing — nothing is typed, so a convincing page collects nothing.
  • Credential stuffing — no passwords exist, so breached-password lists are dead ends.
  • Push fatigue — approval takes a live face check, not a tap, and requests are rate-limited.
  • OTP interception — no codes over SMS or email; SIM swaps find nothing in transit.
  • Keylogging — recorded keystrokes authorize nothing.
  • Helpdesk social engineering — recovery is by face, so there's no reset script to run on a persuasive caller.

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons

Feedback sent

We appreciate your effort and will try to fix the article