4 ms·
I mentioned signals in another comment in this chain and this is a scenario (for banking specifically) where it makes 100% x 100% sense to kill the session for
by throwaway201606 7y ago
I mentioned signals in another comment in this chain and this is a scenario (for banking specifically) where it makes 100% x 100% sense to kill the session for the client's security.
Like kill it totally totally dead!
Unlike other apps, with online banking, the priority is not to keep you connected.
It is to ensure the person carrying out the activity is whom they really say they are and that it is OK for them to do what they are doing with your account
The security posture is "deny" by default and allow if we can verify this person is whom they say they are.
Think about the signals here:
- connection has changed (from wifi to 4g - that gives you a whole bunch of IP, ISP, routing (hops) etc stuff )
- there is a proxy in the chain now (it is possible to identify the hop from phone to laptop)
- view port is still the same (connection is not the user on their phone, they are on their laptop, connected to a phone)
... then the same thing happens all over again but in reverse when you went back to the laptop.
The bank has no idea whether the proxy is a real phone or a MTM intercept especially since the connection did not initiate from that device but switched in flight.
Would totally have required killing the session if I was responsible for defining scenarios here.