logoalt Hacker News

tadfisheryesterday at 10:52 PM1 replyview on HN

How did the service authenticate the user in order to create the new credential within the attacker-controlled app?


Replies

Tharreyesterday at 11:24 PM

With banks, typically a combination of your account number, pin and some confirmation code sent via email or SMS. And of course unregistering your previous device. Not sure where you're going with this though?

show 1 reply