build1 publisher
Cognito ships a new user pool with MFA off and its sign-in risk model disabled
A pool created with the defaults treats a password as the whole authentication factor and scores no risk on the sign-in. In the HackerOne chain a dev.to writeup walks through, either setting turned on would have stopped the takeover.
Publishers:dev.to
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives68
- Confidence52