3 ms·
I'm fairly certain mpesa and all other mobile money platforms just runs on top of plain ol USSD, which similar to SMS isn't encrypted as far as I know. It's "s
by janee 7y ago
I'm fairly certain mpesa and all other mobile money platforms just runs on top of plain ol USSD, which similar to SMS isn't encrypted as far as I know.
It's "secure" because the system requires a pin to authenticate the USSD session. So a SIM swop won't provide an attacker access to the victims account.
I suppose there's a possibility for doing a MITM attack but you'd have to do it between the tower and phone (GSM I think) or between the telco servers (SMPP or SS7), none of which I think are trivial or even possible in some cases
- pgeorgi 7y agoI dug through the literature again, and there are several systems: some using USSD exclusively, others using SIM applications that apparently employ both USSD and SMS for communication. In all case there's some amount of authentication going on, and they all allow retrofitting additional lines of defenses if necessary. 2FA SMS is helpless as long as it's layered on top of plain old SMS (which for political reasons won't become secure).