Hacker News new | ask | show | jobs
by ars 22 days ago
Can't the attacker just man-in-the-middle to the real bank, and show the QR code to the phone?

Does the entire transaction take place on the phone? I don't think that's a good option.