Something’s been bothering me about MFA lately. Over the last few months, I’ve had random push notifications pop up that I definitely didn’t trigger. Most of the time I just hit Deny and move on, but it made me realize how easy it is to go into autopilot, especially when you’re busy or half asleep.
It got me wondering how much MFA actually protects us once credentials are already leaked. At what point does it stop being a security control and start relying entirely on user patience?