Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Or they could balance usability with security and do some sort of throttling at least, there’s no reason to DoS the user with notifications


There was no DoS here.


I know, I wasn't talking literally, but in spirit that's what MFA bombing is – they flood your phone with notifications until you approve one, either accidentally or our of the mental fatigue of having a ton of notifications come in.


That's different in spirit. No denial at all. In fact this action needs to avoid denying service in order to succeed.


It's denying you from using your phone if a notification constantly pops up.


But it doesn't. The screenshot shows avg. only one each 5 min. That is not denying use of phone.


A notification even every few minutes is extremely stressful, and would cause most people to either put their phone in airplane mode (therefore, denying normal use) or accepting the login

But I don't really know why we're arguing over semantics, you understood what I meant.


User can’t use their phone for fear of accidentally touching accept as it scrolls by in notifications.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: