Skip to content

Comment on sPACE Attack: Spoofing eID’s Password Authenticated Connection Establishmentparent

Comments

Yeah, this is a phishing attack replacing the terminal with a compromised one.

The terminal used the PIN for three transactions: The original sign-in process, the attacker's ID verification process for the bank, and a "Selbstauskunft" which essentially is an echo service that returns data read from the card back to the user.

It's not a very performant process and needs to happen near real time.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.