Hacker News new | ask | show | jobs
by kaybe 3601 days ago
I wasn't really able to get the details on that page, but it seems like they do verification by checking personal information like name, birthday and address against a database and ask a few multiple choice questions related to them. How is that not easy to circumvent if the attacker has that set of information? (can probably be obtained by a social attack on the victims bank)

I'm assuming there's something I missed there.

1 comments

I don't think there is. Knowledge-based authentication is extremely vulnerable to identity theft.