I was assuming the user would have to click a button on the phone or something, but I couldn't see it in the video.
I was assuming the user would have to click a button on the phone or something, but I couldn't see it in the video.
... the end user just lost, absent substantially more defense-in-depth on the provider side than just using TFA. TFA mostly helps you against "We lost credentials or a low-privilege session, let's prevent that from escalating to a high-privilege session." If your device is rooted, you'll eventually cough up a high-privilege session, either by passive monitoring or by something more clever like e.g. using your own computer as the MITM to ask you to provide a valid TFA to do something which really only requires a low-privilege session. Now the attacker has both factors. Game set match.
He can steal your cookies, keylog your password/token, poison your dns and compromise your SSL Keys or simply steal a session.