logoalt Hacker News

rsynclast Friday at 7:32 PM1 replyview on HN

Is this true?

The old, standard RSA number generator token key ring device is not permitted in Europe for authorizing bank actions ?


Replies

fphlast Friday at 7:50 PM

Precisely. You can use and old-style hardware token that only generates numbers to log in, but not to authorize an operation such as a money transfer.

The requirement is called "dynamic linking" (the 2FA code must be tied to the specific transaction) and the relevant regulation is PSD2.

show 1 reply