Part 8 · 2 chapters · ~12 min

Account Recovery and Fraud

Recovery as the weakest authentication path, risk scoring for recovery and login, identity proofing with document and liveness checks, cooling-off periods and notifications, account takeover patterns (credential stuffing, SIM swap, social engineering), and device binding.

16

Recovery that is not a backdoor

ACCOUNT RECOVERY WITHOUT A BACKDOOR
recovery must be as strong as the login it replaces
recovery requestrisk checksdevice, IP, velocityproof of identitypasskey on another device, ID + selfiecooling-off periodnotify all channelslimited sessionno payouts for 24-72 hfull access
swipe the figure sideways, or tap expand for full screen
1/5
the weakest door
Attackers do not break strong logins; they use the recovery flow. If an email link or SMS code alone resets everything, that is the real authentication strength.
recovery is the real attack surfaceas strong as the login, or it is the login
17

Account takeover and defences

attackdefence
credential stuffing (reused passwords)breached-password checks, rate limits per account and IP, bot detection, passkeys
SIM swap to intercept SMS codesavoid SMS as sole factor; SIM-swap signals from telcos; device binding
social engineering of support staffsupport cannot bypass verification; scripted checks; maker-checker for account changes
session theftshort sessions, device binding, re-auth for sensitive actions
new device takeovera new device gets limited capabilities until trusted (bound with a passkey, time elapsed)