|
|
|
|
|
by xorcist
2488 days ago
|
|
If the password reset procedure is over SMS, wouldn't any interception of that token have allowed the attackers to access your account and even initiate outgoing transfers? A scam phone call seems like a clumsy way of doing it. It also risks alerting the victim to what's going on. It surprises me that it is legal to conduct banking operations to the general public in this way. In many countries (including all of EU since SCA) that is not the case. |
|