Questions tagged [banks]

Use for questions about security practices used by banks and other financial institutions.

220 questions
0
votes
1 answer

Is it possible to bypass 2FA and access bank account in this system?

Nowadays, any credit/debit card transaction made online (at least for mine) requires one to enter the card details (Account No., Expiry Date, CVV etc). In the end, a OTP (One Time Pass) is sent to the mobile number linked to that Credit/Debit card…
Vasu Deo.S
  • 175
  • 1
  • 7
0
votes
2 answers

How secure is Libra considering Visa and Mastercard are behind it?

Libra is the upcoming cryptocurrency by Facebook which Facebook claims is supported by variety of tech companies including but not limited to Mastercard, Paypal and Visa. Facebook also enforces a real name policy, and at this stage we all know that…
0
votes
1 answer

Online payment integration requires handling my bank credentials. Why?

When doing a payment integration what would be the reasons the payment gateway would require your bank credentials instead of redirecting the client to his or her bank website? The context of my question can be found on the Personal Finance & Money…
Pips
  • 105
  • 2
0
votes
1 answer

Data leakage in internet-only services

Nowadays, internet-only services became very popular, for example, direct bank and many others. The advantage of such services is you don't have to spend the time to get to the office in order to get a service, everything can be done online.…
gar
  • 3
  • 2
0
votes
0 answers

Is there a security issue with fit4less requiring bank information and not simply card number?

When I set up timed payments I tend to prefer setting them up through my credit card. As this tends to be more reliable in case of over charges, etc. For example spotify goes through my credit card. The setup was done by entering my credit card…
akozi
  • 101
  • 2
0
votes
1 answer

Fake bank text message

I recently tried to use my card to buy something on my phone for £29.99. My card was declined so I used a different card and the payment went through. A couple minutes later I get a message from a number, the same as my bank's, telling me "you've…
Michal
  • 1
0
votes
1 answer

Pinhole communication with air gapped network

A long time ago ago I worked for a small bank. We used a physically separated network to host our internal servers that handled all the transactions, as well as the workstations accessing the system. One day someone came along and wanted to build a…
mgefvert
  • 1
  • 3
0
votes
1 answer

FooCoin, a BitCoin on an encrypted smartphone OS = flawed?

Please help me with a theoretical Bitcoin equivalent called FooCoins that are encrypted inside small phone electronics that are difficult to modify and hack, using a closed source OS. BitCoins use the fastest processors to mine coins and verify…
LifeInTheTrees
  • 849
  • 1
  • 7
  • 13
0
votes
1 answer

Is an exploit that exposes the balance of any account in the bank a high risk exploit?

I have found an exploit to get account balance information for any account in my bank website. What is the level of this exploit (risk, medium, low)? and is it ethical to ask for a prize or money before telling them what is the problem?
badr aldeen
  • 111
  • 4
0
votes
1 answer

Storing bank account details securely

I'm writing some software which has an invoicing component. Is it safe to store a bank account number and an associated sort code in a database if I use encryption? Can anything be stolen using just these two numbers? The numbers have to be…
userqwert
  • 101
  • 1
0
votes
1 answer

chipTan in combination with bank's portal or mobile application

I use chipTAN for authentication in banking-context because I think it's the better second factor. Till now I use the bank´s portal via a browser on my PC. In future I want to use the mobile application provided by the bank. Now is the question is…
mucki
  • 1
  • 3
0
votes
1 answer

Multifactor Authentication over Single Channel

I recently changed banks and the new bank's mobile-banking service has made me ask some questions. The phone is authenticated/registered with the bank who must be keeping something like an tuple. At this point, all other…
Richard
  • 385
  • 2
  • 9
0
votes
1 answer

Forgot Password Vulnerability

I visited my bank's website today with the intention of logging in to do bank stuff. I entered my username and hit enter on accident without entering a password. It took me to a page to select how I wanted to get my security code in other words the…
ninja coder
  • 101
  • 1
0
votes
2 answers

"1234 1234 XXXX 1234" in a statement from an ATM

I got a statement from an ATM after I withdrew money where my card number was encoded like this: 1234 1234 XXXX 1234 where 1234 -- the real digits of my card. Since there're only 4 digits hidden, how vulnerable is it?
Incerteza
  • 2,177
  • 3
  • 15
  • 22
0
votes
1 answer

Securing a public computer meant for banking

I sometimes visit my bank personally to handle certain formalities. Inside there is a booth containing a computer and all equipment necessary to log in to the online banking service. The computer is meant for people who wish to access their account…
rhino
  • 103
  • 4
1 2 3
14
15