Exploit Techniques
The attacker triggers unanticipated MFA prompts to the user’s device. Potentially after phishing the credentials.
Under pressure or fatigue, the user accepts to stop the bombardment
This attack works because:
Possession of the username and password is sufficient to initiate an MFA prompt
The request can be initiated from any browser
There is not correlation between the location of the user/phone and the origin of the request
While anomaly detection techniques can help, they are ultimately just raising the bar, not fixing the root problem.
Allthenticate eliminates MFA Fatigue
By only accepting requests from browsers that were marked as trusted by the user using secure authentication and relying on the laws of physics to prove proximity, you can eliminate MFA fatigue while offering one of the smoothest login experiences possible.

One-Time Secure Pairing

Proving Proximity (with Bluetooth)
Once trust is established with the browser and the phone is paired with the computer (connected over Bluetooth), users are re-logged-in automatically by sending a cryptographic challenge to the phone through the local computer over Bluetooth — confidently asserting that phone is near the computer that loaded the website.
With your phone acting as a proximity-bound hardware token, the user experience is surreal.
Logins either require the phone to be physically close or a typical secure MFA interaction.
