Уровень 0 · материалов: 3
В кластер входят документы, описывающие конкретные технические уязвимости или недостатки механизмов проверки подлинности в банковских сервисах, и не входят документы об общих правилах кибербезопасности.
Общие признаки: проблемы аутентификации, риски финансовой безопасности, технические недостатки защиты в банковском ПО
Группа выше: Уязвимости финансовых и мобильных приложений
Смысл: The text highlights a perceived security vulnerability in the T-Bank Android app where device-level authentication is erroneously treated as application-level authentication for the 'Quick Entry' feature, prioritizing user convenience over financial security.
The T-Bank Android app's 'Quick Entry' feature allows access to bank accounts without a PIN if the phone was unlocked for any reason in the last five minutes, a design choice the bank claims is intentional.
Смысл: The main idea is that using the same device for both the banking application and the receipt of authentication SMS codes creates a significant security loophole that can lead to financial loss if the device is stolen or left unattended.
Sberbank's mobile app authentication is insecure because it allows access via SMS codes delivered to the same device, effectively bypassing password requirements.
Смысл: The text highlights a potential security vulnerability in Tinkoff Bank's OTP generation, where specific transaction types produce predictable codes with matching first and third digits, reducing the overall entropy and security.
An analysis of 234 Tinkoff Bank OTPs reveals that for certain transactions, the first and third digits always match, suggesting a flawed and predictable random number generator.