What the attacker wants
Human login attackers want something that works again later: a password, OTP, recovery factor, or ceremony fragment that converts into a second session on another device. The estate question is whether the product still mints ambient authority from human input.
