4 ms·
Thanks! In the Swedish supreme court case I quoted above: Background information: - Sweden has a public personal identification number for every citizen (exc
by tpmx 3y ago
Thanks!
In the Swedish supreme court case I quoted above:
Background information:
- Sweden has a public personal identification number for every citizen (except for like 10k people with protected identities)
- The four main banks in Sweden have collaborated to create something called "Bank Id". It's often used as a secure authentication tool combined with the personal identification number (something you have - the cert in the mobile app, something you know - PIN or face id).
Someone convinced an elderly person over the phone to authorize the creation of a new Bank Id on the attacker's phone. This was fairly complicated and required the old person to use their physical RSA SecurID token. The court found that the elderly person had behaved reasonably well and that the attacker was very competent.
Still, the supreme court felt that the bank should have been more careful about letting strangers steal their money.
- avianlyric 3y agoIn the UK authorised push payment fraud, where customers are tricked into authorising payments to fraudster accounts has a similar smell to Swedish case you mention. Rulings by the regulators and courts have reached basically identical conclusions to the Swedish courts. Fs the customers acted in a reasonable manner, then it’s the banks failure, customers aren’t expected to become security and fraud experts just to access their bank accounts.