Ko močna avtentikacija ni dovolj: forenzični pogled na bančno goljufijo z oddaljenim dostopom
Synopsis
The paper discusses the rise of banking fraud, where attackers are using advanced social engineering (phone calls) and legitimate remote access tools (e.g. AnyDesk) instead of looking for technical vulnerabilities. Although strong authentication (SCA) reduces the overall risk, current approaches to electronic banking are vulnerable, as they combine all security factors on a single compromised device. Advanced technologies such as the upcoming Secure Payment Confirmation (SPC) standard can bridge the gap. Banks currently often shift liability to victims due to “gross negligence”. Recent case law and experience with alternative dispute resolution (ADR) confirm that succumbing to manipulation should not automatically constitute gross negligence. Upcoming European legislation (PSR and PSD3) will explicitly prohibit this and introduce clearer liability for banks and conditions for refunding funds in the event of successful impersonation. The focus of cybersecurity is thus shifting from verifying identity (“who you are”) to confirming the actual understanding and intent of the transaction.
Downloads
Published
Categories
License

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.





