**No Rate Limiting:** Duo Security (at the time) did not limit the number of push notifications within a time window - **No Number Matching:** The push notification asked only to "approve" or "deny" — it did not require the user to enter a number displayed on the login screen - **No Context Informat