Hacker News new | ask | show | jobs
by WhyNotHugo 32 days ago
When I'm redirected to my bank, my bank shows my account name and some details (including a custom per-device avatar). Spoofing that would require gathering these small details.

Some banks have a custom device to scan a QR code, where the device generates a signing token but also shows the transaction details too. Regrettably, these are not too common, despite being the safest variant.