Lock screen notifications and leaking OTPs

Jan

Who's the Boss?
Staff member
Joined
May 24, 2010
Messages
14,789
Reaction score
13,438
Location
The Rabbit Hole
Lock screen notifications and leaking OTPs

South Africans who use their smartphones to receive one-time pins (OTPs) for banking transactions or to access important accounts should ensure these do not appear on their lock screens.

Criminals with access to someone's device could use the feature to perform banking transactions or make changes to their accounts, with devastating financial consequences for their victims.
 
Good advice. One of the first things I turn off are Lock Screen notification. Terrible idea. Like when your banking app displays your balance in bold 42pt font on start up for everyone to see as you go in to do a payment or other transaction. Silly.
My banking app doesn't do that, that is rather silly if it does.
 
FaceID and I would hope its droid equivalents solve this neatly.

Non-issue if you aren’t an idiot.
 
I disagree. If it were a setting you chose to turn on, sure, but there are lots of people who don’t know you can turn this off. It’s on by default IIRC.

Then iPhone users should also turn on the new lockdown mode setting under privacy and security which prevents thieves from adding their biometrics without authentication if the phone is not near your home or business (that said it should always ask for authentication by default IMO - can’t believe it’s not on always).
You're confusing Lockdown mode with Stolen Device Protection.
 
Regarding the other concern brought up here;
With Standard Bank's app the easy-balance-view option is off by default, surely the same with all bank apps?
 
Last edited:
I disagree. If it were a setting you chose to turn on, sure, but there are lots of people who don’t know you can turn this off. It’s on by default IIRC.
For which bank?
 
It hasn't been a thing for years. Capitec and FNB now use the app for notifications. Slow news day with all the repeats here.

We discussed this yesterday - some / many banks still give the option to get OTP's instead, even AFTER registering for the app....

Agenda much?
:giggle:
 
On virtual cards, I've had a few fails trying to use them and just yesterday noticed a "regret, we don't accept virtual cards" at the car rental place - though understandable in their case I guess.
So... same question, different reason, lol... which bank?
 
More troublesome is that at some banks you cannot force confirmation before transactions are done on your accounts. Apparently the payment processing platform gets to decide this, and the bank allows the payment.
 
More troublesome is that at some banks you cannot force confirmation before transactions are done on your accounts. Apparently the payment processing platform gets to decide this, and the bank allows the payment.

Don't have that problem, but I've found that if you do a screen dump of the on-screen confirmation (on a PC etc.) , many places will accept that as official enough.
 
Top
Sign up to the MyBroadband newsletter
X