Resisting phishing and impersonation
The planned set-up combines phishing-resistant authentication, authorised devices and independent confirmation of sensitive actions. A convincing message or a synthetic voice must not be enough to trigger an export or a change of access.