|
|
|
|
|
by dvdkhlng
2488 days ago
|
|
Just realizing that a phishing-attack like this is nowadays impossible in the EU: proper two-factor authentication is mandatory now (Revised Directive on Payment Services, PSD2), even just for login. TAN-codes generated for transactions need to incorporate the data of the transaction (recipient and amount), so that a phished TAN cannot be used to authorize a different transaction. I think even a simple SMS TAN may not be allowed any more (could be MITM-abused to authorize a different than the intended transaction). Here is a summary of what customers and phishers have to face since september: https://wso2.com/library/articles/2019/06/strong-customer-au... |
|
In fact, because it makes checking recent transactions that much less convenient, it probably made me less safe because I do it much less often.