3 ms·
Thanks for taking the time to explain this: it does indeed seem clear that they are just doing username and password detection for access. A followup question:
by throwaway201606 7y ago
Thanks for taking the time to explain this: it does indeed seem clear that they are just doing username and password detection for access.
A followup question: I have lived in Europe and have accounts in banks in Ireland. For those accounts, actually executing any financial transaction requires entering a one time token generated by a device that uses your debit card and PIN.
Like so:
https://www.youtube.com/watch?v=kEOEQzC8-Fc https://www.youtube.com/watch?v=kEOEQzC8-Fc
Do the banks you tested have a similar setup?
Just trying to find out if these specific banks have chosen to control view transactions with just the username / password but require some other additional authentication for actual financial transactions.
- viraptor 7y agoNone of them required extra authorisation to get data. (even transactions going back 5+ years) They did have the SMS validation when adding new transfer targets, but not for executing transactions to existing contacts - which is potentially an issue if you can pay off a different credit card just by changing the reference field.