• Cyber Safety
  • Posts
  • Your MFA Is Strong — Until Someone Gets Tired of Approving It

Your MFA Is Strong — Until Someone Gets Tired of Approving It

In partnership with

How Jennifer Aniston’s LolaVie brand grew sales 40% with CTV ads

For its first CTV campaign, Jennifer Aniston’s DTC haircare brand LolaVie had a few non-negotiables. The campaign had to be simple. It had to demonstrate measurable impact. And it had to be full-funnel.

LolaVie used Roku Ads Manager to test and optimize creatives — reaching millions of potential customers at all stages of their purchase journeys. Roku Ads Manager helped the brand convey LolaVie’s playful voice while helping drive omnichannel sales across both ecommerce and retail touchpoints.

The campaign included an Action Ad overlay that let viewers shop directly from their TVs by clicking OK on their Roku remote. This guided them to the website to buy LolaVie products.

Discover how Roku Ads Manager helped LolaVie drive big sales and customer growth with self-serve TV ads.

The DTC beauty category is crowded. To break through, Jennifer Aniston’s brand LolaVie, worked with Roku Ads Manager to easily set up, test, and optimize CTV ad creatives. The campaign helped drive a big lift in sales and customer growth, helping LolaVie break through in the crowded beauty category.

MFA Doesn’t Automatically Stop Account Takeovers

Multi-factor authentication creates an important barrier, but attackers have developed techniques that target the human behind the authentication request rather than the technology itself.

Repeated Prompts Can Become an Attack

After obtaining a password, an attacker may trigger authentication requests repeatedly, hoping the legitimate user eventually approves one just to make the notifications stop.

Fatigue Creates Dangerous Autopilot

Employees who approve MFA requests frequently throughout the day can develop automatic behavior. That habit makes an unexpected malicious request easier to accept without scrutiny.

Hire anyone, anywhere — compliant in under 3 days

Found the right hire, but no entity in their country? Remote becomes the legal employer — with contracts, benefits, and tax setup handled, plus direct access to the same in-house team that runs payroll locally.

Attackers Can Add Social Engineering

A fake support call or message can make the request more convincing: “We’re testing your account — please approve the notification you’re about to receive.”

Unexpected Authentication Requests Are Security Alerts

Users should never approve a login they didn't initiate. Repeated unsolicited prompts should be reported immediately because they may indicate that a password has already been compromised.

Move Toward Phishing-Resistant Authentication

Use passkeys or hardware security keys where practical, enable number matching when push authentication remains necessary, monitor repeated MFA attempts, and investigate abnormal login behavior. MFA works best when attackers can't trick users into completing it for them.

Analytics on Live Data Without Leaving Postgres

When analytics on Postgres slows down, most teams add a second database. Then they manage pipelines, sync lag, and drift forever. TimescaleDB extends Postgres instead. Analytics run on live data, in the database you already have. No pipeline. No migration. No new query language.