Part 8 · 2 chapters · ~12 min
Account Recovery and Fraud
Recovery as the weakest authentication path, risk scoring for recovery and login, identity proofing with document and liveness checks, cooling-off periods and notifications, account takeover patterns (credential stuffing, SIM swap, social engineering), and device binding.
16
Recovery that is not a backdoor
ACCOUNT RECOVERY WITHOUT A BACKDOOR
recovery must be as strong as the login it replaces
swipe the figure sideways, or tap expand for full screen
1/5
the weakest door
Attackers do not break strong logins; they use the recovery flow. If an email link or SMS code alone resets everything, that is the real authentication strength.
recovery is the real attack surfaceas strong as the login, or it is the login
17
Account takeover and defences
| attack | defence |
|---|---|
| credential stuffing (reused passwords) | breached-password checks, rate limits per account and IP, bot detection, passkeys |
| SIM swap to intercept SMS codes | avoid SMS as sole factor; SIM-swap signals from telcos; device binding |
| social engineering of support staff | support cannot bypass verification; scripted checks; maker-checker for account changes |
| session theft | short sessions, device binding, re-auth for sensitive actions |
| new device takeover | a new device gets limited capabilities until trusted (bound with a passkey, time elapsed) |