• Cyber Safety
  • Posts
  • Your Password Reset Process Might Be Weaker Than Your Password

Your Password Reset Process Might Be Weaker Than Your Password

In partnership with

Blu Dot surpasses 2,000% ROAS with self-serve CTV ads

Home furniture brand Blu Dot blew up on CTV with help from Roku Ads Manager. Here’s how:

After a test campaign reached 211,000 households and achieved 1,010% ROAS, the brand went all in to promote its annual sales event. It removed age and income constraints to expand reach and shifted budget to custom audiences and retargeting, where intent was strongest.

The results speak for themselves. As Blu Dot increased their investment by 10x, ROAS jumped to 2,308% and more page-view conversions surpassed 50,000.

“For CTV campaigns, Roku has been a top performer,” said Claire Folkestad, Paid Media Strategist, Blu Dot. “Comping to our other platforms, we have seen really strong ROAS… and highly efficient CPMs, lower than any other CTV partner we've worked with.”

Using Roku Ads Manager, the campaign moved from a pilot to a permanent performance engine for the brand.

Attackers Don’t Always Need to Guess the Password

When authentication is difficult to defeat directly, attackers can target the recovery process instead. Password resets can become an alternative route into otherwise well-protected accounts.

Recovery Channels Become Security Dependencies

Personal email addresses, phone numbers, security questions, and support workflows may all be used to recover access. If one of those channels is compromised, the primary account can become vulnerable too.

The ice cream shop that makes money when it's cold

28 Wishes sells ice cream in Los Angeles. Below 70°F, sales fall about 20%. So the owners put about $20 a day into Kalshi weather markets, taking the cold side. The days that keep customers away now pay something back. See how other owners are doing it

Public Information Makes Security Questions Weak

Birthdays, schools, family names, job history, and other personal details can often be discovered through social media or data breaches. Information that feels private isn't necessarily secret.

Account Recovery Can Bypass MFA

A poorly designed recovery process may allow an attacker to reset authentication methods, register a new device, or replace existing MFA protections after convincing a support team they are the legitimate user.

Recovery Events Deserve Extra Monitoring

Password resets, MFA changes, new recovery addresses, and device registrations should be treated as sensitive security events — especially when several happen within a short period.

Secure the Way Users Get Back In

Strengthen identity verification, minimize weak recovery methods, alert users when security settings change, monitor suspicious resets, and require additional approval for privileged accounts. Your authentication is only as strong as the process designed to bypass it when someone says, “I forgot my password.”

Your agents work while you sleep

Give a Skydive agent an ongoing responsibility and they’ll handle it on schedule, every time.

Have them prep your morning report, research new leads, monitor customer feedback, or keep projects moving overnight. You wake up, the work is already done.