Android and iOS

Unintended approval in push authentication

OAuth, passkeys, biometrics, device registration and recovery.

Identity and sessions1 min readEditorial methods

Repeated prompts can encourage thoughtless acceptance. Show clearly which request is being approved.

Evaluation approach

Design context, attempt limits and rejection. Users should be able to report requests they did not initiate.

Application example

Provide device or session context for new-device approval and treat repeated unsolicited requests as a separate risk event.

Limits and considerations

Another tap alone does not establish strong authentication.

Is rejection easy to find?

Make unsolicited requests easy to decline and report. Repeated prompts need limits and investigation; notification pressure is not a security success measure.

Checks and decisions

  • Show context
  • Limit requests
  • Provide reporting

Sources

The primary references above provide the technical basis. Example workflows and evaluation suggestions are this publication’s explanations, not independent test results for a particular product.