Liberty SMS - Unauthorized access to IT infrastructure

I assume they were talking about a service that accesses your bank account on your behalf - you supply your credentials. Really stupid idea - it's just bad practice. They should be negotiating with banks for certificate based R/O API access or other similar secure method.
Indeed. I know 22seven do it as well which is why I have a separate read only online banking account for them to use
 
I assume they were talking about a service that accesses your bank account on your behalf - you supply your credentials. Really stupid idea - it's just bad practice. They should be negotiating with banks for certificate based R/O API access or other similar secure method.
Unfortunately SA banks and APIs don't go in the same sentence
 
Indeed. I know 22seven do it as well which is why I have a separate read only online banking account for them to use

Yeah, it's a horrible idea. They want access to all sorts. Very insecure.
 
I assume they were talking about a service that accesses your bank account on your behalf - you supply your credentials. Really stupid idea - it's just bad practice. They should be negotiating with banks for certificate based R/O API access or other similar secure method.
And how do you provide r/o access without a...
 
You store a one way hash. Not an encrypted password.
Agreed. It has to be stored... But securely

Edit: but let's be honest. If you're using a password manager and 2FA it's irrelevant if they retrieve your password
 
Last edited:
Agreed. It has to be stored... But securely

Edit: but let's be honest. If you're using a password manager and 2FA it's irrelevant if they retrieve your password

Who uses password managers for their banking account? Also, although I think it's stupid, it's less risk to store an encrypted banking password on a password manager with devs who aren't resident in your country. Also, in the case of Liberty and these other apps, who holds the keys to this encrypted pw?
 
Who uses password managers for their banking account? Also, although I think it's stupid, it's less risk to store an encrypted banking password on a password manager with devs who aren't resident in your country. Also, in the case of Liberty and these other apps, who holds the keys to this encrypted pw?

Hence the 2FA comment...
 
And how do you provide r/o access without a...

It's in the post you quoted. Liberty negotiate with banks to set up a read only API that the banks users can turn on or revoke via their internet banking profile. They then authorise the app to access their transactional data. Of they want, they can deauth it at will. That way nobody gets full access to their banking portal even in the event of a breach.

Now if Liberty can't get that right, they have no business offering an insecure alternative.
 
It's in the post you quoted. Liberty negotiate with banks to set up a read only API that the banks users can turn on or revoke via their internet banking profile. They then authorise the app to access their transactional data. Of they want, they can deauth it at will. That way nobody gets full access to their banking portal even in the event of a breach.

And how do you grant access to the r/o api without a...
 
And how do you grant access to the r/o api without a...

Not sure what you're saying. Liberty never get your password if that's what you're asking... only your bank. Access is granted via the bank's systems to Liberty's domain.
 
Not sure what you're saying. Liberty never get your password if that's what you're asking... only your bank. Access is granted via the bank's systems to Liberty's domain.

So anyone can have r/o access to your account without you ever giving permission? Or you log into your account to grant permission using your...
 
So anyone can have r/o access to your account without you ever giving permission? Or you log into your account to grant permission using your...

:erm: you log into your BANK account with your BANK password and your LIBERTY account with your LIBERTY password as it should be.
 
Not sure what you're saying. Liberty never get your password if that's what you're asking... only your bank. Access is granted via the bank's systems to Liberty's domain.

:crylaugh::crylaugh::crylaugh::crylaugh:

Access is granted to Liberty's domain.

:crylaugh::crylaugh::crylaugh::crylaugh:
 
And this password is stored...

No. Password is not stored. It is salted and hashed and the hash is stored... on Liberty's side for the Liberty system and on the banks side for the banks system.
 
:crylaugh::crylaugh::crylaugh::crylaugh:

Access is granted to Liberty's domain.

:crylaugh::crylaugh::crylaugh::crylaugh:

Yep. Liberty is granted their own API key that is only valid for read only requests from their domain to the bank. They don't need your banking credentials.
 
Yep. Liberty is granted their own API key that is only valid for read only requests from their domain to the bank. They don't need your banking credentials.

And please tell us how you are going to store this API key.
Also how a read only API key differs from a read only bank user account.
 
Top
Sign up to the MyBroadband newsletter
X