|
|
|
|
|
by archi42
2488 days ago
|
|
Here we have ChipTAN - I put my card into a special reader (some photodiodes plus keypad and display), hold the diode-end of the reader onto my PC display and a flickering image on the website transfers some info to the reader. On the reader I then see some info on the transaction (IBAN and amount), plus a TAN. I then enter that TAN on the banks website. So an attacker would need to alter the image (simple) and cause a collision (hopefully difficult) or somehow abuse an error in the reader firmware. It seems there is now a QR variant of that (which increases the attack surface since now it has to understand a more complex data format). If my bank would have had me install an App or use SMS 2FA I would have kindly asked them to .... off (or, if they think their "2FA" is safe, just connect their mobile phones to this totally unsuspicious looking USB device). ChipTAN on wikipedia:
https://en.wikipedia.org/wiki/Transaction_authentication_num... |
|