| ▲ | tadfisher 2 hours ago | |||||||
How did the service authenticate the user in order to create the new credential within the attacker-controlled app? | ||||||||
| ▲ | Tharre 2 hours ago | parent [-] | |||||||
With banks, typically a combination of your account number, pin and some confirmation code sent via email or SMS. And of course unregistering your previous device. Not sure where you're going with this though? | ||||||||
| ||||||||